Information Carrier Authentication Using Physical Token Signatures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge is to authenticate information carriers like CDs and DVDs without managing the detected response data of physical tokens in a database, as large databases are impractical for managing such data, especially for low-cost carriers susceptible to piracy.
Innovation Solution
The method involves forming authentication data from detected response data, signing it with a trusted party's private key, and storing the signed data on the information carrier, allowing verification without a database, using physical tokens as one-way functions to generate cryptographic data and applying delta-contracting functions for noise compensation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If detected response data of physical tokens is managed in a database, then authentication reliability is improved, but device complexity and storage requirements increase significantly
Solution Approach 1:
The patent extracts the authentication verification process from the central database and relocates it to the information carrier itself. The signed authentication data is written directly onto the carrier, enabling verification without querying a central database. This extracts the verification function from the complex database system and embeds it in the carrier, reducing overall system complexity while maintaining authentication reliability.
Solution Approach 2:
The information carrier becomes self-sufficient by storing its own signed authentication data. During verification, the carrier provides its authentication data and the signed copy stored on itself, allowing the verification to be performed locally without external database assistance. This self-service approach eliminates the need for complex database management infrastructure.
2Reliability
If a database is used to store detected response data, then authentication security is improved, but storage requirements and costs increase
Solution Approach 1:
The patent extracts the authentication data from the database and places it directly on the information carrier. Only essential authentication data (challenge data and signed authentication data) is stored on the carrier, while the database stores minimal or no response data. This extraction significantly reduces storage requirements while maintaining security through cryptographic signing.
Solution Approach 2:
The patent uses inexpensive information carriers that can be mass-produced with embedded authentication data. Each carrier is a low-cost, disposable object containing its own authentication credentials, eliminating the need for expensive, centralized database storage infrastructure. The carrier itself becomes the secure storage medium.
3Reliability
If physical tokens are used as one-way functions, then uncloneability is improved, but manufacturing precision requirements increase
Solution Approach 1:
The patent changes the physical parameters of the information carrier to create unique, uncloneable characteristics. Instead of requiring precise manufacturing of complex physical tokens, the carrier's inherent physical variations (such as manufacturing tolerances, material properties, or geometric deviations) are exploited as the basis for unique authentication data. This parameter change approach converts manufacturing imprecision into a security feature.
Data Source
AI summary
The present invention relates to a method of enabling authentication of an information carrier, the information carrier comprising a writeable part and a physical token arranged to supply a response upon receiving a challenge, the method comprising the following steps; applying a first challenge to the physical token resulting in a first response, and detecting the first response of the physical token resulting in a detected first response data, the method being characterized in that it further comprises the following steps; forming a first authentication data based on information derived from the detected first response data, signing the first authentication data, and writing the signed authentication data in the writeable part of the information carrier. The invention further relates to a method of authentication of an information carrier, as well as to devices for both enabling authentication as well as authentication of an information carrier.


