Cryptographic Protection Device Dongle Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Customers face challenges in verifying the authenticity and lawful ownership of products, as traditional methods rely on serial numbers that can be reproduced, weakening the association between products and certificates, and lack cryptographic verification.
Innovation Solution
A method using cryptographically associated keys and a public transaction directory to authenticate a protection device and a dongle, ensuring the association is secure and tamper-proof, with a signed combined identifier verifying the authenticity of both, and a contract script for conditional unlocking.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If serial numbers are used to associate products with certificates, then the association can be established, but the reliability and security of the association is weakened because serial numbers can be reproduced
Solution Approach 1:
The patent replaces the mechanical/physical serial number system with a cryptographic system using public key infrastructure. Instead of relying on unique serial numbers that can be copied, the system uses cryptographic key pairs where the public key serves as the identifier and the private key provides authentication. This substitution fundamentally strengthens the association reliability while maintaining verification simplicity through cryptographic proof.
Solution Approach 2:
The patent introduces a certificate authority (CA) as an intermediary that issues digital certificates binding public keys to product identities. This intermediary layer enables trusted verification of the association between products and certificates without requiring direct complex verification processes. The CA-signed certificates act as mediators that simplify the verification complexity while ensuring high association reliability.
2Reliability
If cryptographic authentication is implemented using public key infrastructure, then the security and authenticity verification is strengthened, but the device complexity and operational complexity increase
Solution Approach 1:
The protection device performs cryptographic authentication operations autonomously using its embedded private key and cryptographic module. The device automatically verifies the dongle's authenticity and generates unlock commands without requiring manual cryptographic operations from the user. This self-service approach maintains high authenticity verification while preserving operational simplicity for the end user.
Solution Approach 2:
The patent uses a pre-configured cryptographic association between the protection device and dongle, established through a trusted intermediary (certificate authority), to simplify operations. The cryptographic credentials are pre-loaded and automatically exchanged, eliminating the need for users to manually manage complex cryptographic keys or perform complex verification procedures, thus maintaining ease of operation.
3Reliability
If a distributed public transaction directory like blockchain is used to verify ownership, then the security against forgery is enhanced, but the verification time and system complexity increase
Solution Approach 1:
The patent performs preliminary actions by pre-configuring cryptographic key pairs and associations between the protection device and dongle before deployment. The public keys and cryptographic credentials are embedded in advance, allowing for rapid verification without requiring time-consuming real-time cryptographic key generation or exchange processes. This preliminary setup reduces verification time while maintaining high security through the immutable blockchain record of the pre-established associations.
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
Method for suspending a physical protection of an object (1) achieved by a protection device (2), wherein a host device (10) receives a first public key, a second public key, a third public key and a signed combined identifier incorporating the first public key and the second public key, wherein the signed combined identifier is signed with a third private key, which third private key is cryptographically associated with the third public key; the host device (10) requests a search of transactions associated with the signed combined identifier within the public transaction directory (12); the host device (10) authenticates at least the first public key and the second public key using a signature of the signed combined identifier and using the third public key; the host device (10) authenticates the protection device (2) using the first public key and the dongle (6) using the second public key and sends an unlock request to the dongle (6) if the search of the transaction directory (12) yields at least one transaction and the first and second public keys, the protection device (2) and the dongle (6) are authentic; and the dongle (6) receives the unlock request and in reaction sends an unlock command controlling an actuator (3) of the protection device (2) to suspend the physical protection of the protected object (1).