Authentication Management Unit for Mutual Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In information processing systems, constructing a mutual authentication system where a higher-level device and a lower-level device with multiple slave devices authenticate each other is complex and time-consuming, leading to inefficiencies and redundancy.
Innovation Solution
The implementation of an authentication management unit in the lower-level device that facilitates mutual authentication between the higher-level device and multiple slave devices by transmitting and receiving authentication information, allowing the higher-level device to authenticate the lower-level device and slave devices through a centralized management system, using a common key cryptogram method for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the higher-level device executes mutual authentication with each slave device individually, then security performance is improved, but the processing time is prolonged and the system becomes redundant
Solution Approach 1:
The patent combines multiple slave devices into a single lower-level device for authentication purposes. The lower-level device aggregates the authentication capabilities of all slave devices, allowing the higher-level device to perform a single mutual authentication with the lower-level device instead of multiple separate authentications with each slave device. This merging approach maintains security while significantly reducing processing time and eliminating redundancy.
Solution Approach 2:
The lower-level device is designed to serve multiple functions: it acts as both an independent authentication entity and as a representative of multiple slave devices. By giving the lower-level device universal authentication capability that covers all slave devices, the system eliminates the need for individual slave device authentications while maintaining comprehensive security coverage.
2Reliability
If the higher-level device executes mutual authentication with each slave device individually, then authentication completeness is improved, but the system complexity increases
Solution Approach 1:
The patent merges the authentication functions of multiple slave devices into a single lower-level device. This consolidation reduces system complexity by eliminating the need for the higher-level device to manage and execute separate authentication protocols with each slave device, while still achieving complete authentication coverage through the unified lower-level device.
Solution Approach 2:
The lower-level device acts as an intermediary between the higher-level device and the slave devices. It receives authentication requests from the higher-level device and internally coordinates with the slave devices, shielding the higher-level device from the complexity of individual slave device communications while ensuring complete authentication.
3Reliability
If the system uses individual authentication for each slave device, then security coverage is improved, but the ease of operation deteriorates
Solution Approach 1:
The lower-level device is equipped with universal authentication functionality that covers all slave devices. This multi-functional design allows the system to maintain comprehensive security coverage while significantly improving ease of operation, as the higher-level device only needs to interact with the lower-level device through a standardized authentication interface regardless of the number of slave devices present.
Data Source
AI summary
A control unit for controlling a card reader. The control unit includes an authentication management unit for transmitting/receiving information to/from a host and each of a first encryption magnetic head device and a second encryption magnetic head device to mutually authenticate each other. The authentication management unit includes (1) a commanding means for commanding one of the first encryption magnetic head device and the second encryption magnetic head device to create lower-level information for authentication, according to a request on authentication from the host, (2) a sharing means for transmitting the lower-level information for authentication received from the above-mentioned one device to the other device for the purpose of sharing it and (3) a transmission means for transmitting the lower-level information for authentication, having been shared in all of the first encryption magnetic head device and the second encryption magnetic head device, to the host.


