Authentication Object for Multi-Subject Secure Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for establishing protected electronic communication among multiple subjects are either too complex and secure but user-unfriendly or too simple and insecure, failing to provide a balanced level of protection that is manageable for most users in scenarios like public transport, banking, and healthcare.

Innovation Solution

A method involving the creation and configuration of an authentication object that enables secure communication and information transfer among three or more subjects through the establishment of multiple secure authenticated channels, using a combination of authentication methods and local communication to manage rights and security information, ensuring both security and user-friendliness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complex authentication systems like PKI are used to provide high security among multiple subjects, then security level is improved, but device complexity and ease of operation deteriorate making users unable to handle them

Engineering Contradiction:
Improvesecurity levelVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into distinct functional modules: authentication objects stored on user devices, authentication channels between subjects, and rights control information separate from communication data. This modular segmentation reduces overall system complexity while maintaining security through organized, manageable components that users can interact with individually rather than as a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces authentication objects as intermediary elements that mediate between users and the complex authentication infrastructure. These objects encapsulate cryptographic credentials and authentication logic, shielding users from the underlying complexity of PKI systems while enabling secure multi-subject authentication through simple object-based interactions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If simple authentication methods like passwords are used among multiple subjects, then ease of operation is improved, but security level deteriorates becoming insufficient for protected communication

Engineering Contradiction:
Improveuser-friendlinessVSAvoidsecurity level
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent creates authentication objects that are copies of cryptographic credentials stored locally on user devices. These copied authentication objects enable users to authenticate without repeatedly entering passwords or complex credentials, simplifying operation while maintaining security through cryptographic verification of the copied authentication data.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent performs preliminary authentication setup by creating and storing authentication objects on user devices before actual communication occurs. This preliminary action includes generating cryptographic key pairs and storing rights control information in advance, so that during actual communication users can simply present their authentication objects without performing complex authentication procedures.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If separate authentication systems are established for each user-provider pair among multiple subjects, then security level is improved through dedicated channels, but device complexity and loss of time increase due to repeated authentication procedures

Engineering Contradiction:
Improvesecurity levelVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates authentication objects with multi-functionality that can be used across multiple authentication channels and with multiple subjects. A single authentication object stored on a user device can participate in secure communication with any number of subjects that have corresponding rights control information configured, eliminating the need for separate authentication systems for each user-provider pair while maintaining dedicated channel security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges multiple authentication credentials and rights into a single authentication object that combines cryptographic keys, subject identifiers, and access rights. This consolidation allows users to authenticate with multiple subjects using one unified object rather than managing separate credentials for each relationship, reducing authentication time while maintaining security through the combined object's cryptographic protection.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If traditional two-subject authentication methods are extended to multiple subjects, then security coverage is improved, but device complexity increases making the system unmanageable for most users

Engineering Contradiction:
Improvesecurity coverageVSAvoidmanageability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables self-service authentication where users independently present their authentication objects to multiple subjects without requiring manual configuration or intervention from other subjects. The authentication system automatically verifies credentials and enforces rights control information, allowing users to manage their own authentication across multiple subjects without needing to understand or configure the underlying complex security infrastructure.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements dynamic authentication where the behavior and permissions of authentication objects can change based on the context of communication with different subjects. Rights control information embedded in authentication objects dynamically determines which subjects can access which resources, allowing the system to adapt to different communication scenarios without requiring static pre-configuration for every possible subject combination.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10686777B2Method for establishing protected electronic communication, secure transfer and processing of information among three or more subjects
Publication Date: 2020.06.16 ADUCID
  • US10686777B2 patent drawing
  • US10686777B2 patent drawing
  • US10686777B2 patent drawing

AI summary

A method of establishing protected electronic communication, secure transfer and processing of information among three or more subjects in which, at first, a first secure authenticated channel is created using an authentication system between a first subject and a second subject, and this channel is used by the first subject, in co-operation with the second subject, to create an authentication object stored on the second subject and provided with authentication object methods, whereas the first subject configures methods of authentication object by assigning to each method of the authentication object a rights control information for at least one other subject and optionally also a rights control information for the first subject to use at least one method of the authentication object, and then the first secure authenticated channel is closed.