Building-Linked Digital Certificate Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network authentication systems primarily focus on server-side authentication, leaving client-side authentication underdeveloped, with limited solutions for reliable client authentication across multiple platforms and high vulnerability to fraud due to the ease of loss, theft, or misuse of hardware-based authentication methods.

Innovation Solution

A system that authenticates network clients by associating a unique digital certificate with a fixed physical building location, using the last mile connection as a secure component, and employing a security server to verify the physical connection ID, providing a two-level authentication process involving hardware security devices and digital certificates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-based authentication methods (secure dongles, smart cards) are used for client authentication, then authentication capability is provided, but security is compromised due to ease of loss, theft, or exchange

Engineering Contradiction:
Improveauthentication capabilityVSAvoidvulnerability to loss, theft, or exchange
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces hardware-based authentication mechanisms (secure dongles, smart cards) with a software-based authentication system that uses digital certificates and cryptographic keys. This substitution eliminates the physical vulnerabilities of hardware tokens while maintaining authentication capability through software-based identity verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent uses digital certificates as virtual copies of identity credentials, replacing physical authentication tokens. These digital certificates can be securely stored and transmitted without the risks associated with physical hardware loss or theft, while providing equivalent authentication functionality.

Inventive Principle:
Principle #26Copying

2Reliability

If server-side authentication is implemented, then security for server transactions is improved, but client-side authentication remains underdeveloped with no clear advantages for clients

Engineering Contradiction:
Improveserver-side securityVSAvoidclient-side authentication coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal authentication framework using digital certificates that can be applied to both server-side and client-side authentication. This multi-functional system allows any network participant (client or server) to authenticate themselves, providing consistent security benefits across all parties rather than limiting authentication to servers only.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent separates authentication capabilities into independent digital certificate units that can be individually issued to different network participants. This segmentation allows clients to obtain their own authentication credentials independently, enabling versatile client-side authentication without requiring server-side control for each authentication event.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If hardware security components are distributed to consumers, then authentication is enabled, but effectiveness is limited due to consumer inability to keep them secured

Engineering Contradiction:
Improveauthentication availabilityVSAvoidsecurity maintenance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces physical hardware security components that require consumer custody with software-based digital certificates that can be securely managed without physical protection. This substitution maintains authentication availability while eliminating the security maintenance burden on consumers.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent implements automated certificate management systems that handle security concerns without requiring consumer intervention. The system automatically manages certificate issuance, storage, and protection, providing authentication availability while maintaining security through automated processes rather than consumer-dependent physical security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP1905191B1Network user authentication system and method
Publication Date: 2014.09.03 VERIMATRIX INC
  • EP1905191B1 patent drawingFigure 1
  • EP1905191B1 patent drawingFigure 2
  • EP1905191B1 patent drawingFigure 3

AI summary

In a network user authentication system, a network user is identified for authentication purposes using the unique identifier for a dedicated physical communication line associated with the building in which the network user is located or a digital certificate which is associated with a secure component or communication line physically attached to a building. An authentication server initially verifies the identification of the dedicated communication line to be associated with a network service subscriber or issues a unique digital certificate to be associated with the dedicated communication line for authentication purposes. The digital certificate may be stored in a building gateway or in an edge site module which is connected to the secure components of a plurality of buildings and stores unique digital certificates for each building.