Anonymous Integrity Attestation via Intermediary Authentication Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional integrity attestation systems face challenges in maintaining anonymity between user devices and service providing servers, leading to potential hacking and phishing attacks, and require separate authentication protocols for session-key sharing and channel protection.

Innovation Solution

A system and method that issues a secret key based on the validity of a user device's security module, using an anonymous authentication protocol to ensure integrity attestation between user devices and service providing servers, thereby maintaining anonymity and eliminating the need for separate authentication protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional integrity attestation systems are used, then device authentication is achieved, but anonymity between user devices and service providing servers is lost

Engineering Contradiction:
Improvedevice authenticationVSAvoidanonymity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a third-party authentication server as an intermediary that mediates between the user device and service providing server. This intermediary verifies device authentication through the security module while maintaining anonymity by not directly linking the user device to specific services, thus resolving the contradiction between authentication reliability and anonymity preservation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate authentication protocols are used for session-key sharing and channel protection, then security coverage is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidauthentication protocols
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication protocol with session-key sharing and channel protection mechanisms into a single integrated protocol. This unified approach allows the system to achieve comprehensive security coverage for both authentication and key exchange while reducing overall system complexity by eliminating the need for separate protocols.

Inventive Principle:
Principle #5Merging (Combining)

3Object-affected harmful factors

If anonymity is maintained in integrity attestation, then hacking and phishing attacks are prevented, but authentication reliability may be compromised

Engineering Contradiction:
Improvehacking and phishing attacksVSAvoidauthentication reliability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent employs self-service mechanisms where the security module autonomously performs authentication and key generation without requiring direct identification or disclosure of user device information. This self-service approach maintains anonymity by avoiding information leakage while ensuring authentication reliability through cryptographic verification within the security module itself.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7979696B2System and method of providing security
Publication Date: 2011.07.12 SAMSUNG ELECTRONICS CO LTD
  • US7979696B2 patent drawing
  • US7979696B2 patent drawing
  • US7979696B2 patent drawing

AI summary

A method and system for providing security between a service providing server and a user device, the system including: a user device to request a service and to transmit a packet including a first public key; an authentication server to receive the packet, to authenticate the user device based on the first public key, to generate a secret key if the user device is authenticated, and to transmit the secret key to the user device; and a service providing server to check an integrity of the user device by using information for an integrity attestation having the secret key, and to provide the service to the user device according to the integrity of the user device. When the remote integrity attestation of the user device is implemented by the service providing server, the anonymity of the user device is guaranteed and the integrity of the user device is authenticated.