Client Device Certificate Authentication for Hearing Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Hearing devices face security challenges due to open standard-based wireless communication interfaces, which can lead to unauthorized access, battery exhaustion attacks, and other security threats, compromising the device's functionality and integrity.

Innovation Solution

A client device with a processing unit, memory unit, and interface that generates and transmits authentication messages using client device keys and certificates, ensuring secure communication by encrypting certificates and including authentication identifiers, thereby controlling access and preventing unauthorized interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If open standard-based wireless communication interface is used for hearing device, then ease of operation and compatibility are improved, but security and reliability deteriorate due to unauthorized access and battery exhaustion attacks

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary authentication actions before allowing communication. The client device and hearing device exchange authentication messages and verify certificates in advance, establishing secure credentials before any data transmission occurs. This prevents unauthorized devices from accessing the hearing device while allowing legitimate devices to communicate freely.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces authentication messages and certificates as intermediary elements between the client device and hearing device. These intermediaries carry authentication information and verify identities, acting as a mediator that enables secure communication without compromising the open wireless interface. The intermediary authentication mechanism allows the system to maintain ease of operation while improving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication messages with encrypted certificates are transmitted, then security and reliability are improved, but device complexity increases due to key generation and encryption processes

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into distinct components: key generation, certificate encryption, authentication message creation, and verification. By dividing the complex authentication mechanism into separate manageable steps, the system can implement robust security without overwhelming the device architecture. Each segment can be optimized independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements self-service authentication where the hearing device and client device autonomously generate and verify authentication messages without requiring external intervention. The devices independently manage their own keys and certificates, reducing the need for complex external authentication infrastructure and simplifying the overall system while maintaining high security.

Inventive Principle:
Principle #25Self-service

3Reliability

If client device key and certificate are stored in memory unit, then security is improved through controlled access, but loss of information increases risk if keys are compromised

Engineering Contradiction:
ImprovesecurityVSAvoidkey compromise risk
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements parameter changes by using multiple cryptographic keys with different purposes (authentication key, encryption key) and managing their lifecycle dynamically. Keys can be updated, revoked, or regenerated based on security events. This flexibility reduces the impact of key compromise since not all keys need to be replaced simultaneously, and the system can adapt to different security scenarios.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent performs preliminary key establishment and certificate issuance before potential compromise scenarios can occur. Authentication credentials are pre-configured and verified before critical operations, reducing the window of vulnerability. If a key is compromised, the preliminary authentication framework allows for rapid detection and response by invalidating specific credentials before they can cause significant damage.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9887848B2Client device with certificate and related method
Publication Date: 2018.02.06 GN HEARING AS
  • US9887848B2 patent drawing
  • US9887848B2 patent drawing
  • US9887848B2 patent drawing

AI summary

A client device for hearing device communication, includes: a processing unit; a memory unit; and an interface; wherein the memory unit has a client device key and a client device certificate stored therein; and wherein the processing unit is configured to receive a connection response comprising a hearing device identifier via the interface, generate one or more keys including a certificate key based on the hearing device identifier and the client device key, and obtain an authentication message based on the certificate key and the client device certificate; wherein the processing unit is configured to obtain the authentication message by encrypting the client device certificate with the certificate key to obtain an encrypted client device certificate, and including the encrypted client device certificate in the authentication message; and wherein the interface is configured to transmit the authentication message.