Authentication Management Unit for Mutual Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In information processing systems, constructing a mutual authentication system where a higher-level device and a lower-level device with multiple slave devices authenticate each other is complex and time-consuming, leading to inefficiencies and redundancy.

Innovation Solution

The implementation of an authentication management unit in the lower-level device that facilitates mutual authentication between the higher-level device and multiple slave devices by transmitting and receiving authentication information, allowing the higher-level device to authenticate the lower-level device and slave devices through a centralized management system, using a common key cryptogram method for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the higher-level device executes mutual authentication with each slave device individually, then security performance is improved, but the processing time is prolonged and the system becomes redundant

Engineering Contradiction:
Improvesecurity performanceVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines multiple slave devices into a single lower-level device for authentication purposes. The lower-level device aggregates the authentication capabilities of all slave devices, allowing the higher-level device to perform a single mutual authentication with the lower-level device instead of multiple separate authentications with each slave device. This merging approach maintains security while significantly reducing processing time and eliminating redundancy.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The lower-level device is designed to serve multiple functions: it acts as both an independent authentication entity and as a representative of multiple slave devices. By giving the lower-level device universal authentication capability that covers all slave devices, the system eliminates the need for individual slave device authentications while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If the higher-level device executes mutual authentication with each slave device individually, then authentication completeness is improved, but the system complexity increases

Engineering Contradiction:
Improveauthentication completenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication functions of multiple slave devices into a single lower-level device. This consolidation reduces system complexity by eliminating the need for the higher-level device to manage and execute separate authentication protocols with each slave device, while still achieving complete authentication coverage through the unified lower-level device.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The lower-level device acts as an intermediary between the higher-level device and the slave devices. It receives authentication requests from the higher-level device and internally coordinates with the slave devices, shielding the higher-level device from the complexity of individual slave device communications while ensuring complete authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the system uses individual authentication for each slave device, then security coverage is improved, but the ease of operation deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidease of construction
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The lower-level device is equipped with universal authentication functionality that covers all slave devices. This multi-functional design allows the system to maintain comprehensive security coverage while significantly improving ease of operation, as the higher-level device only needs to interact with the lower-level device through a standardized authentication interface regardless of the number of slave devices present.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8863238B2System and method for mutual authentication
Publication Date: 2014.10.14 SANKYO SEIKI MFG CO LTD
  • US8863238B2 patent drawing
  • US8863238B2 patent drawing
  • US8863238B2 patent drawing

AI summary

A control unit for controlling a card reader. The control unit includes an authentication management unit for transmitting/receiving information to/from a host and each of a first encryption magnetic head device and a second encryption magnetic head device to mutually authenticate each other. The authentication management unit includes (1) a commanding means for commanding one of the first encryption magnetic head device and the second encryption magnetic head device to create lower-level information for authentication, according to a request on authentication from the host, (2) a sharing means for transmitting the lower-level information for authentication received from the above-mentioned one device to the other device for the purpose of sharing it and (3) a transmission means for transmitting the lower-level information for authentication, having been shared in all of the first encryption magnetic head device and the second encryption magnetic head device, to the host.