Authentication Device Management Key Pair Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods struggle to efficiently manage multiple terminals, particularly in corporate settings where system administrators need to collectively register and manage authentication settings for numerous devices, leading to increased workload and complexity.
Innovation Solution
An authentication device management system that generates key pairs for users, including a private key for authentication and a public key for verification, and manages these keys through a centralized device, allowing for collective management and validation of authentication devices without transmitting sensitive information over networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a public key authentication method is used between user terminals and service providers, then authentication security is improved, but management complexity increases when dealing with multiple terminals
Solution Approach 1:
The patent introduces a management server as an intermediary between authentication devices and service providers. The management server generates key pairs, manages private keys securely, and distributes public keys to service providers. This intermediary structure maintains the security benefits of public key authentication while centralizing management operations, thereby reducing the complexity of managing multiple authentication devices across the organization.
2Adaptability or versatility
If each terminal performs independent authentication registration with multiple service providers, then authentication flexibility is improved, but administrative workload increases
Solution Approach 1:
The management server performs preliminary actions by pre-generating key pairs for authentication devices before they are needed for actual authentication. The server stores private keys securely and makes public keys available to service providers in advance. This preliminary key management eliminates the need for administrators to perform repetitive registration operations at each terminal-service provider interaction, significantly reducing administrative workload while maintaining authentication flexibility.
3Ease of operation
If private keys are transmitted over the network for authentication device registration, then device setup is simplified, but security risks increase
Solution Approach 1:
The patent extracts the private key from the network transmission process entirely. The management server generates private keys and stores them securely in its own storage system, never transmitting them over the network. Only public keys, which are mathematically derived from private keys but cannot reveal the private key, are transmitted to service providers. This extraction of the sensitive private key from the transmission path maintains device setup simplicity while eliminating the security risks of network transmission.
Data Source
AI summary
An authentication device management device includes a generating unit, a registration unit, a transmission unit, and a responding unit. The generating unit generates a pair of a first key to attach a signature with respect to an authentication result obtained by an authentication device that performs personal authentication of a user, and a second key to verify the signature attached to the first key. The registration unit registers, in association with each other, the key identifier that identifies the generated key pair and user identification information. The transmission unit transmits the first key generated by the generating unit to the authentication device used by the user. When the responding unit accepts a transmission request for the second key related to the authentication device in which the first key transmitted by the transmission unit has been set, the responding unit responds by instructing the authentication server to transmit the second key.


