Combined Power-Data Authentication for Fast Device Repowering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing power systems lack efficient methods to uniquely identify and authenticate power requestors, particularly in environments with high power demands, leading to potential security risks and inefficiencies in power delivery.
Innovation Solution
Implementing a system that uses cryptographic authentication to verify the identity of power-consuming devices through a combined power/data interface, ensuring secure and efficient power delivery by integrating power authentication logic and hardware storage modules to manage device credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional power delivery authentication is used, then security against Man-in-the-Middle attacks is improved, but connection time and power delivery speed deteriorate due to full authentication requirements
Solution Approach 1:
The system performs preliminary authentication by storing cryptographic credentials (public keys, certificates) in the device's hardware storage module before power delivery is needed. When connecting to a power source, the device can quickly present these pre-stored credentials for verification, avoiding the need for time-consuming real-time authentication while maintaining security against Man-in-the-Middle attacks.
Solution Approach 2:
The patent introduces cryptographic tokens and certificates as intermediaries between the power-consuming device and the power source. These cryptographic credentials serve as a trusted mediator that enables rapid mutual authentication without requiring direct complex verification protocols, thus reducing connection time while preserving security.
2Measurement precision
If cryptographic authentication is implemented for each power connection, then device identity verification is improved, but system complexity deteriorates due to credential management requirements
Solution Approach 1:
The device's hardware storage module autonomously manages cryptographic credentials, performing self-service functions such as storing public keys, generating digital signatures, and validating certificates without requiring external credential management infrastructure. This self-contained approach maintains precise identity verification while minimizing system complexity.
Solution Approach 2:
The patent replaces complex mechanical or procedural credential management systems with cryptographic mechanisms. Instead of physical credential verification or complex authentication protocols, the system uses mathematical cryptography (public-key infrastructure, digital signatures) to achieve precise identity verification with simpler operational complexity.
3Productivity
If fast repowering is enabled through cached credentials, then power delivery speed is improved, but security risk deteriorates due to potential credential caching vulnerabilities
Solution Approach 1:
The system performs preliminary cryptographic authentication and caches the results in hardware storage before fast repowering operations. The cached credentials are pre-validated cryptographic tokens that enable rapid subsequent power deliveries without re-authentication, achieving high speed while maintaining security through the initial rigorous authentication process.
Solution Approach 2:
The hardware storage module provides beforehand cushioning by securely storing and managing cached cryptographic credentials in a protected environment. This pre-established secure credential storage cushions against security vulnerabilities that might arise from repeated authentication operations, allowing fast repowering while mitigating potential security risks through prior secure credential establishment.
Data Source
AI summary
A computing device connected to a power source via a combined power/data connection obtains an authentication request from the power source. The authentication request includes a freshness mechanism provided by the power source. The computing device signs an authentication response with a private key associated with a verified identity stored on the computing device. The authentication response includes the freshness mechanism. The computing device provides the authentication response to the power source, and receives power from the power source.


