Cryptographic Device Identifier Generation and Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for authenticating users across multiple online services lack a secure and efficient method to block lost or compromised cryptographic devices, requiring users to individually notify each service provider, which is cumbersome and prone to data merging issues between providers.

Innovation Solution

A method for generating and blocking identifiers for pairs of cryptographic devices and computer systems using a '2-way calculation' involving secret keys, where a blocking system requires both the first and second subsystems to block the device, ensuring anonymity and preventing unauthorized use across multiple services with a single command.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users individually notify each service provider to block a lost cryptographic device, then the device can be blocked at each service, but the process becomes cumbersome and time-consuming

Engineering Contradiction:
Improveblocking effectivenessVSAvoidblocking time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces a blocking system as an intermediary that centralizes the blocking process. Instead of users contacting each service provider individually, the blocking system receives blocking requests and distributes blocking information to all relevant service providers automatically, significantly reducing the time and effort required for blocking while ensuring comprehensive coverage

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If service providers share user data for blocking purposes, then blocking efficiency improves, but user anonymity is compromised and data merging issues arise

Engineering Contradiction:
Improveblocking efficiencyVSAvoiduser anonymity
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent extracts and separates the blocking functionality from the service providers themselves, placing it in a dedicated blocking system. This allows service providers to participate in the blocking process without directly sharing user data with each other, maintaining user anonymity while achieving efficient coordinated blocking through the intermediary system

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If a centralized blocking system stores all second secret keys, then blocking can be performed efficiently, but the system becomes a single point of failure and security risk

Engineering Contradiction:
Improveblocking speedVSAvoidsystem security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the centralized storage of secret keys by introducing a trusted third party that holds the second secret keys, while the blocking system only stores blocking information. This segmentation prevents the blocking system from being a single point of failure for secret key storage, while still enabling efficient blocking operations through the distributed architecture

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2399218B1Method for generating an identifier
Publication Date: 2019.02.27 BUNDESDRUCKEREI GMBH
  • EP2399218B1 patent drawingFigure 1
  • EP2399218B1 patent drawingFigure 2
  • EP2399218B1 patent drawingFigure 3

AI summary

The invention relates to a method for generating an identifier for identifying a pair, wherein the pair comprises a cryptographic device (100) and a computer system (1, 2,...,i,..I), wherein the cryptographic device comprises a first secret key (102), wherein a second secret key (118. i) is associated with the computer system, wherein a locking system (120) for accessing the second secret key of the computer system is provided, wherein the locking system comprises a third secret key (126), and wherein the following steps are carried out for generating the identifier: Generating a second public key (116. i) from the second secret key and a third public key (116. i) associated to the third secret key by means of the locking system, transmitting the second public key (116. i) to the computer system (i), generating the identifier by the cryptographic device from the first secret key and the second public key.