Authentication Device Lightweight Signature Scheme
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication systems are overly restrictive, particularly in updating authentication public key certificates and require significant data storage and transmission due to partial message recovery in signature schemes, leading to inefficiencies.
Innovation Solution
The proposed solution involves an authentication device with a memory and processing logic that stores a device authentication private key, public key certificate, and configuration root certificate, enabling secure authentication and configuration operations, along with a lightweight signature scheme that reduces data size through padding and encryption, allowing for efficient message recovery without relying on hash functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional signature schemes with partial message recovery are used, then authentication security is maintained, but data storage and transmission volume increases significantly
Solution Approach 1:
The patent extracts only the essential authentication elements (signature and minimal metadata) from the conventional certificate format, removing redundant hashed text and meta-data. This extraction principle reduces the certificate size while preserving the core authentication security function through the use of RSA signatures and selective inclusion of necessary fields such as version, type, subject, and public key information.
Solution Approach 2:
Instead of including the full hashed message with the signature (conventional approach), the patent inverts the approach by including only the signature and essential metadata, relying on the cryptographic properties of RSA signatures to provide authentication without requiring the transmitted message to be embedded in the certificate.
2Adaptability or versatility
If authentication public key certificates are made updateable, then system adaptability improves, but security risks and complexity increase
Solution Approach 1:
The patent implements dynamic certificate management by allowing the authentication device to generate new key pairs and update certificates over time. The system transitions from static pre-provisioned certificates to dynamic, updateable credentials while maintaining security through cryptographic verification of each update operation and revocation mechanisms for compromised credentials.
Solution Approach 2:
The patent establishes preliminary security measures including root of trust establishment, certificate signing by authorized entities, and revocation list maintenance before updates are performed. These preliminary actions create a secure framework that enables subsequent certificate updates without compromising security, by pre-defining the rules and authorities that govern future updates.
3Measurement precision
If comprehensive authentication metadata is included in certificates, then verification accuracy improves, but data transmission and storage requirements increase
Solution Approach 1:
The patent applies local quality by including different types of information in different certificate fields based on their specific verification needs. Essential verification elements (public key, subject, issuer, validity period) are included with appropriate detail, while avoiding redundant or excessive metadata. The certificate structure is optimized to include only the local information necessary for each specific verification function.
Solution Approach 2:
The patent uses partial action by including only the subset of metadata necessary for authentication verification, rather than comprehensive message content. The certificate includes partial information (essential authentication elements) sufficient for verification accuracy while deliberately excluding excessive data such as full message hashes and redundant metadata fields.
Data Source
AI summary
A public key architecture (160) includes a dual certificate hierarchy which facilitates two independent authentication functions. One of the authentication functions authenticates an authentication device (164) to a verification device (166). The other authentication function authenticates a configuration device (162) to the authentication device (164). In some embodiments, the authentication process uses a lightweight certificate formed in conjunction with a lightweight signature scheme (370).


