Credential Generation for Secure Device-Server Mutual Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current remote device management systems for communications devices are prone to errors and security compromises due to the need for out-of-band communication and user input of passwords, and do not efficiently manage changes in server passwords.

Innovation Solution

A method for generating device-specific and server-specific passwords using a shared cryptographic function based on unique identifiers and a service provider key, eliminating the need for user input and out-of-band communication, allowing for secure mutual authentication between devices and management servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If out-of-band communication and user input are used for password communication, then device management can be established, but security is compromised and errors occur

Engineering Contradiction:
Improveauthentication securityVSAvoiduser input requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The device autonomously generates its own device password using its unique identifier and a shared secret key, eliminating the need for user input or out-of-band communication. The device also autonomously generates server passwords for authentication with multiple management servers, making the system self-configure and self-manage without human intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The device is pre-programmed with a password generation algorithm that uses its unique identifier and a shared secret key to generate both device passwords and server passwords. This preliminary setup allows the device to independently create authentication credentials without requiring out-of-band communication or user input during deployment.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If manual password programming is performed, then device management sessions can be initiated, but time consumption and complexity increase

Engineering Contradiction:
Improvedevice management setup speedVSAvoidpassword management process
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The device automatically generates its own device password and server passwords for multiple management servers using a deterministic algorithm based on its unique identifier and shared secret. This eliminates manual password programming and reduces setup time while maintaining secure authentication across multiple servers without increasing device complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The device uses a single password generation algorithm to create both device passwords for server authentication and server passwords for device authentication. This universal approach allows the device to manage multiple management servers efficiently without requiring separate password management processes for each server type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If server passwords are changed manually, then security can be updated, but device re-programming is required which increases time and complexity

Engineering Contradiction:
Improvepassword update securityVSAvoiddevice re-programming time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The device is pre-configured with a password generation algorithm that can independently create server passwords for any management server. When server passwords need to be updated, the device can regenerate its server passwords using the same algorithm with updated parameters, eliminating the need for manual re-programming and reducing update time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables dynamic password generation where the device can independently create and update server passwords in response to server changes. The password generation algorithm adapts to new server credentials without requiring physical re-programming of the device, allowing flexible and timely password updates while maintaining authentication security.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8438391B2Credential generation management servers and method for communications devices and device management servers
Publication Date: 2013.05.07 NOKIA OF AMERICA CORP
  • US8438391B2 patent drawing
  • US8438391B2 patent drawing
  • US8438391B2 patent drawing

AI summary

Systems and methods are described for establishing credentials at a device and at a device management server for the purpose of exchanging secure credentials in order to mutually authenticate the device and the server. A credential generation algorithm is described which uses a plurality of seeds, including the hardware identity of the device, the server identity, and a shared private key, to generate two sets of credentials, one to be used by the device and the other to be used by the device management server. The credentials are exchanged between the device and the server during any session, thereby assuring mutual authentication.