Authentication Object for Multi-Subject Secure Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for establishing protected electronic communication among multiple subjects are either too complex and secure but user-unfriendly or too simple and insecure, failing to provide a balanced level of protection that is manageable for most users in scenarios like public transport, banking, and healthcare.
Innovation Solution
A method involving the creation and configuration of an authentication object that enables secure communication and information transfer among three or more subjects through the establishment of multiple secure authenticated channels, using a combination of authentication methods and local communication to manage rights and security information, ensuring both security and user-friendliness.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complex authentication systems like PKI are used to provide high security among multiple subjects, then security level is improved, but device complexity and ease of operation deteriorate making users unable to handle them
Solution Approach 1:
The patent segments the authentication system into distinct functional modules: authentication objects stored on user devices, authentication channels between subjects, and rights control information separate from communication data. This modular segmentation reduces overall system complexity while maintaining security through organized, manageable components that users can interact with individually rather than as a monolithic complex system.
Solution Approach 2:
The patent introduces authentication objects as intermediary elements that mediate between users and the complex authentication infrastructure. These objects encapsulate cryptographic credentials and authentication logic, shielding users from the underlying complexity of PKI systems while enabling secure multi-subject authentication through simple object-based interactions.
2Ease of operation
If simple authentication methods like passwords are used among multiple subjects, then ease of operation is improved, but security level deteriorates becoming insufficient for protected communication
Solution Approach 1:
The patent creates authentication objects that are copies of cryptographic credentials stored locally on user devices. These copied authentication objects enable users to authenticate without repeatedly entering passwords or complex credentials, simplifying operation while maintaining security through cryptographic verification of the copied authentication data.
Solution Approach 2:
The patent performs preliminary authentication setup by creating and storing authentication objects on user devices before actual communication occurs. This preliminary action includes generating cryptographic key pairs and storing rights control information in advance, so that during actual communication users can simply present their authentication objects without performing complex authentication procedures.
3Reliability
If separate authentication systems are established for each user-provider pair among multiple subjects, then security level is improved through dedicated channels, but device complexity and loss of time increase due to repeated authentication procedures
Solution Approach 1:
The patent creates authentication objects with multi-functionality that can be used across multiple authentication channels and with multiple subjects. A single authentication object stored on a user device can participate in secure communication with any number of subjects that have corresponding rights control information configured, eliminating the need for separate authentication systems for each user-provider pair while maintaining dedicated channel security.
Solution Approach 2:
The patent merges multiple authentication credentials and rights into a single authentication object that combines cryptographic keys, subject identifiers, and access rights. This consolidation allows users to authenticate with multiple subjects using one unified object rather than managing separate credentials for each relationship, reducing authentication time while maintaining security through the combined object's cryptographic protection.
4Reliability
If traditional two-subject authentication methods are extended to multiple subjects, then security coverage is improved, but device complexity increases making the system unmanageable for most users
Solution Approach 1:
The patent enables self-service authentication where users independently present their authentication objects to multiple subjects without requiring manual configuration or intervention from other subjects. The authentication system automatically verifies credentials and enforces rights control information, allowing users to manage their own authentication across multiple subjects without needing to understand or configure the underlying complex security infrastructure.
Solution Approach 2:
The patent implements dynamic authentication where the behavior and permissions of authentication objects can change based on the context of communication with different subjects. Rights control information embedded in authentication objects dynamically determines which subjects can access which resources, allowing the system to adapt to different communication scenarios without requiring static pre-configuration for every possible subject combination.
Data Source
AI summary
A method of establishing protected electronic communication, secure transfer and processing of information among three or more subjects in which, at first, a first secure authenticated channel is created using an authentication system between a first subject and a second subject, and this channel is used by the first subject, in co-operation with the second subject, to create an authentication object stored on the second subject and provided with authentication object methods, whereas the first subject configures methods of authentication object by assigning to each method of the authentication object a rights control information for at least one other subject and optionally also a rights control information for the first subject to use at least one method of the authentication object, and then the first secure authenticated channel is closed.


