Authentication Code Convertor for Secure Consumable Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems for multi-function printers face challenges in securely authenticating compatible consumables and replacement parts, particularly due to the high cost of tamper-resistant chips required for public key encryption and the difficulty in mounting these chips to general-purpose personal computers.
Innovation Solution
An authentication system that includes a to-be-authenticated device generating first authentication data, an authentication code convertor converting this data into second authentication data using different encryption keys, and an authentication device authenticating based on the converted data, allowing for secure authentication without the need for tamper-resistant chips on the authentication device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If public key encryption is used for authentication, then authentication security is improved, but the cost of tamper-resistant chips increases
Solution Approach 1:
The authentication system is segmented into two parts: the to-be-authenticated device uses public key encryption with a tamper-resistant chip for high security, while the authentication device uses common key encryption without requiring a tamper-resistant chip. This segmentation allows each component to use the appropriate security level, reducing overall system cost while maintaining authentication security.
Solution Approach 2:
The patent applies asymmetric encryption architecture where the to-be-authenticated device and authentication device use different encryption methods. The to-be-authenticated device uses public key encryption (asymmetric) with a tamper-resistant chip, while the authentication device uses common key encryption (symmetric) without a tamper-resistant chip. This asymmetric approach allows cost reduction at the authentication device while maintaining overall security.
2Reliability
If tamper-resistant chips with public key encryption are mounted on authentication devices, then authentication security is improved, but device complexity increases
Solution Approach 1:
Instead of placing the tamper-resistant chip with public key encryption on the authentication device, the patent inverts the arrangement by placing it on the to-be-authenticated device. This inversion allows the authentication device to use simpler common key encryption without a tamper-resistant chip, reducing device complexity while maintaining authentication security through the reversed architecture.
3Ease of manufacture
If common key encryption is used on the authentication device, then cost is reduced, but authentication security may be compromised
Solution Approach 1:
The authentication system segments the security functions: the to-be-authenticated device handles public key encryption and digital signature verification (high security functions), while the authentication device handles common key encryption (lower security requirements). This segmentation allows the authentication device to use cost-effective common key encryption without compromising overall system security.
Solution Approach 2:
The to-be-authenticated device acts as an intermediary that performs the computationally intensive public key operations and digital signature verification. This intermediary role allows the authentication device to use simpler common key encryption, as the security-critical operations are performed by the to-be-authenticated device before authentication occurs.
Data Source
AI summary
The authentication system includes a to-be-authenticated device for generating a first authentication data; an authentication code convertor for converting the first authentication data generated by the to-be-authenticated device into a second authentication data; and an authentication device for performing authentication of the to-be-authenticated device based on the second authentication data. The first authentication data includes an authentication code obtained by encrypting challenge data output from the authentication device and input to the to-be-authenticated device through the authentication code convertor and predetermined data included in the to-be-authenticated device in accordance with an encryption method using a first encryption key; and the predetermined data included in the to-be-authenticated device. The second authentication data includes an authentication code obtained by encrypting the challenge data output from the authentication device and input to the authentication code convertor and the predetermined data included in the to-be-authenticated device.


