Communication Device Authentication Information Regeneration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In communication systems where multiple networks are interconnected via representative nodes, the existing methods do not provide sufficient network security as all nodes holding the same authentication information can be compromised if one node is seized by a malicious user, leading to impairment of all nodes in the network.
Innovation Solution
A communication device that monitors heartbeat messages from representative nodes, regenerates authentication information by combining distributed data components using Shamir's secret sharing method, and updates this information to ensure secure reconnection to other networks, preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all nodes hold the same authentication information to enable recovery from representative node faults, then network reliability is improved, but network security deteriorates because any node can communicate with other networks and malicious users can compromise the entire network by seizing one node
Solution Approach 1:
The authentication information is divided into multiple data components and distributed to different nodes. Each node holds only a portion of the authentication information, not the complete information. This segmentation ensures that no single node can compromise the entire network while still enabling recovery through combination of components from multiple nodes.
Solution Approach 2:
Different nodes are assigned different data components of the authentication information based on their roles and permissions. The representative node receives all components and can regenerate complete authentication information, while ordinary nodes receive only specific components. This local differentiation allows selective access and maintains security while enabling recovery.
2Ease of repair
If multiple nodes hold authentication information components to enable representative node recovery, then ease of repair is improved, but device complexity increases due to the need for distribution and regeneration mechanisms
Solution Approach 1:
The system enables automatic recovery of representative nodes through self-service mechanisms. When a representative node fails, ordinary nodes automatically transmit their data components to a new representative node candidate, which then automatically regenerates the authentication information and reestablishes network connections without manual intervention.
Solution Approach 2:
Data components of authentication information are pre-distributed to ordinary nodes before any failure occurs. This preliminary distribution ensures that when a representative node fails, the recovery process can immediately proceed using the pre-stored components, eliminating the need for manual authentication information recovery.
3Object-affected harmful factors
If authentication information is distributed among multiple nodes, then network security is improved, but loss of information increases risk as nodes may be compromised individually
Solution Approach 1:
The system prepares multiple data components and distributes them to different nodes in advance, creating a cushion against potential node compromises. Even if some nodes are compromised, the authentication information remains secure because the complete information is not held by any single node, and the system can recover by combining components from uncompromised nodes.
Data Source
AI summary
A communication device includes a processor. The processor monitors a first message that is periodically transmitted from a representative device in a first network. The processor transmits a second message to the communication devices in the first network when the first message is not detected. When plural data components obtained by dividing authentication information have been distributed from the representative device plural communication devices in the first network, the processor receives data components transmitted from the communication devices in the first network in response to the second message. When a specified number of data components are received, the processor regenerates the authentication information from the specified number of data components. The processor generates new authentication information by rewriting at least a portion of the regenerated authentication information. The processor connects to a second network based on the new authentication information.


