AR Device Mutual Authentication via Pairing Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing artificial reality systems lack secure and privacy-preserving methods for device attestation and mutual authentication, especially in multi-device setups where asymmetric communication architectures pose security risks and trust issues between devices.

Innovation Solution

The implementation of a multi-device artificial reality system that uses System on a Chip (SoC) integrated circuits for secure device attestation, where a security server generates pairing certificates specifying permitted device relationships, and these certificates are stored in non-volatile memory for each device, enabling secure boot and mutual authentication without relying on a single device for connectivity, and employing double encryption to prevent data leakage and spoofing attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If asymmetric communication architecture is used where one device communicates through another device, then device connectivity and functionality are improved, but security and trust between devices deteriorate

Engineering Contradiction:
Improvedevice connectivityVSAvoidsecurity and trust
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary device attestation and mutual authentication before establishing communication. Each device is authenticated against a security server prior to pairing, ensuring that only trusted devices can establish asymmetric communication relationships. This preliminary verification maintains security even when devices communicate through intermediaries.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security server acts as an intermediary that verifies device identities and issues pairing certificates. Instead of relying on direct trust between communicating devices, the security server mediates the authentication process, validating that each device is authorized to establish the asymmetric communication relationship.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If device attestation is maintained continuously, then security and authentication reliability are improved, but system complexity and trust management overhead increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidtrust management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts and stores essential authentication information (pairing certificates) in non-volatile memory at the device level. This removes the need for continuous server verification during normal operation, simplifying trust management while maintaining authentication reliability. The authentication credentials are extracted from the complex continuous verification process and stored for efficient use.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Devices perform self-authentication using stored pairing certificates without requiring continuous server intervention. Each device can independently verify the authenticity of paired devices using credentials stored in their non-volatile memory, enabling self-service authentication that reduces system complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

3Reliability

If pairing certificates are stored in non-volatile memory, then device authentication and attestation are improved, but vulnerability to storage attacks and data leakage increases

Engineering Contradiction:
Improvedevice authenticationVSAvoidstorage attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary encryption of pairing certificates before storing them in non-volatile memory. The certificates are encrypted with device-specific keys that are themselves stored securely, creating a layered security approach that protects against storage attacks while maintaining authentication capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security server acts as an intermediary that issues encrypted pairing certificates. The encryption layer between the server and device storage protects the authentication data from direct exposure to attackers, mediating between the need for persistent storage and the need for security.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If mutual authentication is implemented between all devices, then security against spoofing and replay attacks is improved, but communication overhead and authentication time increase

Engineering Contradiction:
Improvesecurity against attacksVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs mutual authentication and certificate verification during the initial device pairing process rather than requiring it for every subsequent communication. This preliminary authentication establishes trusted relationships that can be reused, reducing the time overhead for future communications while maintaining security against spoofing and replay attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses cryptographic copies of authentication data (pairing certificates) that can be verified without transferring the full authentication protocol repeatedly. These certificate copies enable fast verification of device identity without requiring time-consuming re-authentication for each communication operation.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11265721B1Secure device attestation and mutual authentication of artificial reality devices
Publication Date: 2022.03.01 META PLATFORMS TECHNOLOGIES LLC
  • US11265721B1 patent drawing
  • US11265721B1 patent drawing
  • US11265721B1 patent drawing

AI summary

The disclosure describes artificial reality (AR) systems and techniques that enable secure, privacy-preserving device attestation and mutual authentication of multiple devices used concurrently within a multi-device AR system. For example, an AR system comprises a security server configured to generate a pairing certificate that includes information identifying a plurality of devices to be operationally paired with each other. The AR system comprises a peripheral device configured to receive one or more inputs from a user of the AR system, wherein the peripheral device is configured to store the pairing certificate in a non-volatile memory (NVM) of the peripheral device for authenticating the peripheral device and a head-mounted display (HMD) for pairing. The AR system comprises the HMD configured to output artificial reality content, wherein the HMD is configured to store the pairing certificate in a NVM of the HMD for authenticating the HMD device and the peripheral device for pairing.