Authentication Code Portion Switching for Secure Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems using a common encryption key for electric home appliances and peripherals face security risks due to potential decryption and key leakage, especially when peripherals have limited memory capacity to store multiple encryption keys.
Innovation Solution
Implementing an authentication system where both the authentication target device and requesting device use a common encryption key to produce and switch portions of an authentication code, creating multiple encrypted codes to enhance security without needing multiple keys, by encrypting, decrypting, and switching code portions based on specified information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If the same encryption key is used for multiple authentication processes, then the device complexity is reduced and memory requirements are minimized, but the security risk increases due to potential decryption and key leakage
Solution Approach 1:
The patent applies dynamics by making the authentication code change dynamically through switching portions of the code based on switching target portion specifying information. This allows the same encryption key to produce different encrypted codes for each authentication process, enhancing security without requiring multiple keys stored in memory.
Solution Approach 2:
The patent changes parameters of the authentication code by switching different portions of it according to switching target portion specifying information. This parameter change creates variability in the authentication process while using the same encryption key, resolving the contradiction between security and memory constraints.
2Reliability
If multiple encryption keys are prepared for each authentication process, then the security risk of key leakage is reduced, but the device complexity and memory capacity requirements increase
Solution Approach 1:
The patent segments the authentication code into different portions that can be switched independently. By switching specific portions of the authentication code based on specifying information, the system achieves variability equivalent to using multiple keys without actually storing multiple keys in memory.
Solution Approach 2:
The patent creates different encrypted codes by switching portions of the authentication code rather than using different encryption keys. This copying approach generates unique authentication data for each process while maintaining a single key storage, reducing device complexity.
3Productivity
If data encrypted with the same key is exchanged multiple times, then communication efficiency is maintained, but the risk of decryption by third parties increases
Solution Approach 1:
The patent makes the authentication code dynamic by switching portions based on specifying information received during each authentication process. This dynamic change ensures that even though the same encryption key is used, the encrypted data varies each time, preventing successful interception and decryption by third parties.
Solution Approach 2:
The patent changes parameters of the authentication code through switching operations, creating different encrypted outputs for each authentication process. This parameter variation maintains communication efficiency while significantly reducing the risk of data interception and key leakage.
Data Source
AI summary
To provide an authentication system for improving security, using fewer encryption keys. An authentication requesting device (20) and an authentication target device (10) hold common encryption keys. The authentication requesting device (20) encrypts an authentication code, then selects mutually different portions in the authentication code as switching target portions, and sends an encrypted authentication code and information about the switching target portions to the authentication target device (10). The authentication target device (10) switches the switching target portions in a code obtained by decrypting the received code, to thereby produce a switched authentication code, then encrypts the switched authentication code, and sends to the authentication requesting device (20). The authentication requesting device (20) compares the switched authentication code obtained by decrypting the code received with a code obtained by switching the switching target portions of the authentication code to carry out an authentication process for the authentication target device (10).


