Authentication System Dynamic CRL Management for Limited Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems for home electric appliances and controllers do not effectively prevent unauthorized connections due to limitations in certificate revocation list (CRL) management, particularly when device storage capacity is limited, leading to potential unauthorized access.

Innovation Solution

An authentication system that dynamically manages CRLs by transmitting only necessary CRLs to devices with limited storage capacity, ensuring that only authorized controllers are connected by verifying certificate identifiers against the CRL, and allowing devices with ample storage to hold all CRLs for comprehensive authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all devices hold complete CRLs for comprehensive authentication, then security is improved, but devices with limited storage capacity cannot store all CRLs

Engineering Contradiction:
Improveauthentication securityVSAvoidstorage capacity requirement
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the CRL distribution system into two tiers: devices with sufficient storage capacity store complete CRLs locally, while devices with limited storage capacity receive CRL information through peer-to-peer transmission from other devices. This segmentation allows the system to maintain comprehensive authentication security without requiring all devices to have large storage capacities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary devices (devices with larger storage capacity) that act as CRL repositories for the network. These intermediary devices store complete CRLs and provide CRL information to devices with limited storage capacity upon request, enabling small devices to perform authentication without storing all CRLs themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If CRLs are transmitted to all devices, then authentication accuracy is improved, but network bandwidth and transmission time are increased

Engineering Contradiction:
Improveauthentication accuracyVSAvoidCRL transmission time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent extracts the CRL transmission function from the traditional centralized distribution model and implements selective peer-to-peer transmission. Instead of transmitting CRLs to all devices universally, the system extracts and transmits CRL information only to devices that need it and are unable to store complete CRLs, thereby reducing unnecessary network traffic and transmission time.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by transmitting CRL information selectively rather than universally. Devices with limited storage capacity receive only the necessary CRL data through peer-to-peer transmission, while devices with sufficient storage capacity obtain complete CRLs through normal channels, optimizing the balance between authentication accuracy and transmission efficiency.

Inventive Principle:
Principle #16Partial or excessive action

3Quantity of substance

If devices with limited storage do not receive CRLs, then storage requirements are reduced, but unauthorized connections cannot be detected

Engineering Contradiction:
Improvestorage capacity utilizationVSAvoidunauthorized connection detection
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where devices with limited storage capacity can request and receive CRL information from peer devices when needed for authentication. This feedback loop ensures that even though small devices don't store complete CRLs permanently, they can obtain necessary CRL data on-demand to detect unauthorized connections, maintaining security without requiring large storage capacity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10523446B2Authentication system and authentication method
Publication Date: 2019.12.31 PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
  • US10523446B2 patent drawing
  • US10523446B2 patent drawing
  • US10523446B2 patent drawing

AI summary

Upon receiving a new CRL, a device with a large storage capacity in an authentication system detects another device connected to a controller to which this device is connecting, and determines whether or not to transmit the new CRL depending on the magnitude of the storage capacity of the device that has been detected.