Authentication Key Synthesis for Secure Recording Media Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods using authentication keys for accessing data or areas on recording media are not convenient, as they often require sharing sensitive conversion methods and can be insecure when secrets leak.

Innovation Solution

An information processing device generates an authentication key by synthesizing multiple keys assigned to areas of a recording medium, using conversion values derived from device-specific information, allowing for secure and convenient authentication without sharing the conversion method secrets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If authentication is performed using traditional authentication keys, then security is maintained, but convenience deteriorates due to the need to share conversion methods and manage multiple keys

Engineering Contradiction:
Improveauthentication convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication key is segmented into multiple component keys (first key, second key, third key) that are stored in different locations (recording medium, management device). Each key alone is insufficient for authentication, but their combination enables secure authentication. This segmentation eliminates the need to share conversion methods while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A key management device acts as an intermediary that holds the second key and performs the authentication process. The management device combines the first key (from recording medium) and second key (from its storage) to generate the authentication key, eliminating direct sharing of secrets between other parties while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple authentication keys are used for different areas, then security is improved, but device complexity increases due to managing multiple keys and conversion methods

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple authentication keys for different areas are merged into a single unified authentication mechanism. The management device combines the first key (containing area-specific information) and second key to generate authentication keys for multiple areas simultaneously, reducing complexity while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The key management device provides universal authentication functionality for multiple areas and services. A single authentication process using the combined keys can authenticate access to multiple different areas, eliminating the need for separate key management for each area.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If conversion methods are shared for authentication, then ease of operation is improved, but security deteriorates due to potential secret leakage

Engineering Contradiction:
Improveauthentication easeVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The conversion method (secret) is extracted from the authentication process and replaced with a cryptographic key combination mechanism. Instead of sharing conversion methods, the system uses cryptographic keys that can be combined without revealing their individual values or the combination method, eliminating secret sharing while maintaining ease of operation.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3750273B1Information processing device, information processing method, and program
Publication Date: 2024.07.10 SONY GROUP CORP
  • EP3750273B1 patent drawingFigure 1
  • EP3750273B1 patent drawingFigure 2
  • EP3750273B1 patent drawingFigure 3

AI summary

There is provided an information processing device, including: a processing unit configured to perform a calculation using keys assigned to a plurality of areas of a recording medium and generate an authentication key. The processing unit generates the authentication key by performing a calculation using conversion values corresponding to the keys, the conversion values being obtained by converting device-specific information using conversion methods associated with the keys used in the calculation.