Central Unit Authentication Using Dynamic Session Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing tire-pressure monitoring systems face challenges in securely authenticating central units to perform sensitive operations on peripheral units without overloading servers with large data exchanges, particularly in ensuring high security and confidentiality against unauthorized interventions.
Innovation Solution
A method using a secure server to generate a dynamic temporary session key and a shared encryption key for bidirectional communication between central and peripheral units, ensuring authentication through encrypted information exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used for central unit to communicate with peripheral units, then the server can process authentication requests, but the server becomes overloaded with large volumes of data exchanges and security vulnerabilities increase
Solution Approach 1:
The patent extracts the heavy computational burden of authentication from the central server by implementing a distributed authentication mechanism where peripheral units perform local authentication computations. The server only needs to verify cryptographic proofs rather than process complete authentication datasets, significantly reducing server load while maintaining security.
Solution Approach 2:
The patent introduces cryptographic proofs as an intermediary element that mediates between the central unit and peripheral unit authentication. Instead of direct server verification of all authentication data, the cryptographic proof serves as a compact verification token that ensures security while minimizing server processing requirements.
2Productivity
If simple authentication procedures are implemented, then server load is reduced, but security against unauthorized interventions and data confidentiality are compromised
Solution Approach 1:
The patent changes the parameter of authentication from processing large volumes of raw data to verifying compact cryptographic proofs. This parameter transformation maintains strong security guarantees while dramatically improving authentication efficiency and reducing server processing requirements.
Solution Approach 2:
The patent replaces traditional mechanical authentication systems (direct server verification of authentication data) with cryptographic verification mechanisms. The peripheral units generate cryptographic proofs locally, and the server verifies these proofs without handling the underlying authentication sensitive data, achieving both efficiency and security.
3Speed
If the central unit directly communicates with peripheral units without secure server involvement, then data exchange is faster, but unauthorized interventions and piracy risks increase
Solution Approach 1:
The patent implements preliminary authentication actions where peripheral units pre-compute and store cryptographic authentication data. During actual communication, the central unit and peripheral unit perform rapid cryptographic verification using pre-established trust relationships, achieving fast data exchange while maintaining security through pre-configured authentication credentials.
Data Source
AI summary
A method for authenticating a central unit communicating with peripheral units performing measurements, using a server device, each peripheral unit generates a shared encryption key, the server device generates a temporary session key and the same shared encryption key, then performs a first encryption in order to form a first shared dynamic encryption key, then performs a second encryption with the identifier of the central unit in order to give an encrypted central-unit information item as proof of authentication transmitted to the peripheral unit, the peripheral unit performs a reverse decryption in order to obtain the temporary session key, and an encryption with the central-unit identifier and the shared encryption key in order to give an encrypted identifier which is compared with the received encrypted central-unit information item in order to grant its authentication.


