Authentication Device Lightweight Signature Scheme

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication systems are overly restrictive, particularly in updating authentication public key certificates and require significant data storage and transmission due to partial message recovery in signature schemes, leading to inefficiencies.

Innovation Solution

The proposed solution involves an authentication device with a memory and processing logic that stores a device authentication private key, public key certificate, and configuration root certificate, enabling secure authentication and configuration operations, along with a lightweight signature scheme that reduces data size through padding and encryption, allowing for efficient message recovery without relying on hash functions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional signature schemes with partial message recovery are used, then authentication security is maintained, but data storage and transmission volume increases significantly

Engineering Contradiction:
Improveauthentication securityVSAvoiddata storage and transmission volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential authentication elements (signature and minimal metadata) from the conventional certificate format, removing redundant hashed text and meta-data. This extraction principle reduces the certificate size while preserving the core authentication security function through the use of RSA signatures and selective inclusion of necessary fields such as version, type, subject, and public key information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of including the full hashed message with the signature (conventional approach), the patent inverts the approach by including only the signature and essential metadata, relying on the cryptographic properties of RSA signatures to provide authentication without requiring the transmitted message to be embedded in the certificate.

Inventive Principle:
Principle #13The other way round (Inversion)

2Adaptability or versatility

If authentication public key certificates are made updateable, then system adaptability improves, but security risks and complexity increase

Engineering Contradiction:
Improvecertificate updateabilityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic certificate management by allowing the authentication device to generate new key pairs and update certificates over time. The system transitions from static pre-provisioned certificates to dynamic, updateable credentials while maintaining security through cryptographic verification of each update operation and revocation mechanisms for compromised credentials.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent establishes preliminary security measures including root of trust establishment, certificate signing by authorized entities, and revocation list maintenance before updates are performed. These preliminary actions create a secure framework that enables subsequent certificate updates without compromising security, by pre-defining the rules and authorities that govern future updates.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If comprehensive authentication metadata is included in certificates, then verification accuracy improves, but data transmission and storage requirements increase

Engineering Contradiction:
Improveverification accuracyVSAvoidcertificate data size
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent applies local quality by including different types of information in different certificate fields based on their specific verification needs. Essential verification elements (public key, subject, issuer, validity period) are included with appropriate detail, while avoiding redundant or excessive metadata. The certificate structure is optimized to include only the local information necessary for each specific verification function.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent uses partial action by including only the subset of metadata necessary for authentication verification, rather than comprehensive message content. The certificate includes partial information (essential authentication elements) sufficient for verification accuracy while deliberately excluding excessive data such as full message hashes and redundant metadata fields.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11170093B2Authentication device and system
Publication Date: 2021.11.09 NXP BV
  • US11170093B2 patent drawing
  • US11170093B2 patent drawing
  • US11170093B2 patent drawing

AI summary

A public key architecture (160) includes a dual certificate hierarchy which facilitates two independent authentication functions. One of the authentication functions authenticates an authentication device (164) to a verification device (166). The other authentication function authenticates a configuration device (162) to the authentication device (164). In some embodiments, the authentication process uses a lightweight certificate formed in conjunction with a lightweight signature scheme (370).