Communication Device Authentication Information Regeneration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In communication systems where multiple networks are interconnected via representative nodes, the existing methods do not provide sufficient network security as all nodes holding the same authentication information can be compromised if one node is seized by a malicious user, leading to impairment of all nodes in the network.

Innovation Solution

A communication device that monitors heartbeat messages from representative nodes, regenerates authentication information by combining distributed data components using Shamir's secret sharing method, and updates this information to ensure secure reconnection to other networks, preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all nodes hold the same authentication information to enable recovery from representative node faults, then network reliability is improved, but network security deteriorates because any node can communicate with other networks and malicious users can compromise the entire network by seizing one node

Engineering Contradiction:
Improvenetwork reliabilityVSAvoidnetwork security
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication information is divided into multiple data components and distributed to different nodes. Each node holds only a portion of the authentication information, not the complete information. This segmentation ensures that no single node can compromise the entire network while still enabling recovery through combination of components from multiple nodes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different nodes are assigned different data components of the authentication information based on their roles and permissions. The representative node receives all components and can regenerate complete authentication information, while ordinary nodes receive only specific components. This local differentiation allows selective access and maintains security while enabling recovery.

Inventive Principle:
Principle #3Local quality

2Ease of repair

If multiple nodes hold authentication information components to enable representative node recovery, then ease of repair is improved, but device complexity increases due to the need for distribution and regeneration mechanisms

Engineering Contradiction:
Improverepresentative node recoveryVSAvoidauthentication management complexity
Core Design Contradiction:
Ease of repairVSDevice complexity

Solution Approach 1:

The system enables automatic recovery of representative nodes through self-service mechanisms. When a representative node fails, ordinary nodes automatically transmit their data components to a new representative node candidate, which then automatically regenerates the authentication information and reestablishes network connections without manual intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Data components of authentication information are pre-distributed to ordinary nodes before any failure occurs. This preliminary distribution ensures that when a representative node fails, the recovery process can immediately proceed using the pre-stored components, eliminating the need for manual authentication information recovery.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If authentication information is distributed among multiple nodes, then network security is improved, but loss of information increases risk as nodes may be compromised individually

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication information security
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The system prepares multiple data components and distributes them to different nodes in advance, creating a cushion against potential node compromises. Even if some nodes are compromised, the authentication information remains secure because the complete information is not held by any single node, and the system can recover by combining components from uncompromised nodes.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS11323351B2Communication device and communication method for processing authentication information
Publication Date: 2022.05.03 FUJITSU LTD
  • US11323351B2 patent drawing
  • US11323351B2 patent drawing
  • US11323351B2 patent drawing

AI summary

A communication device includes a processor. The processor monitors a first message that is periodically transmitted from a representative device in a first network. The processor transmits a second message to the communication devices in the first network when the first message is not detected. When plural data components obtained by dividing authentication information have been distributed from the representative device plural communication devices in the first network, the processor receives data components transmitted from the communication devices in the first network in response to the second message. When a specified number of data components are received, the processor regenerates the authentication information from the specified number of data components. The processor generates new authentication information by rewriting at least a portion of the regenerated authentication information. The processor connects to a second network based on the new authentication information.