Device Authentication via Identifier Comparison Across Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public safety communication devices using private shared keys (PSKs) are susceptible to compromise, allowing unauthorized access to secure communications, as stolen devices can be used to access secure networks and PSKs can be copied or transferred.

Innovation Solution

A system and method for authenticating communication devices with an application server that compares unique identifiers across different communication networks to grant or deny access, using a gateway registration port and gateway server port to ensure only authorized devices access the secure network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If private shared keys (PSKs) are used to secure communications, then communication security is improved, but device compromise vulnerability increases allowing unauthorized access

Engineering Contradiction:
Improvecommunication securityVSAvoiddevice compromise vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication capability from the physical device by implementing a separate authentication mechanism that does not rely on PSKs stored in the device. The authentication is performed by comparing device identifiers against a registered identifier in the network, separating the authentication function from the communication security key storage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary authentication mechanism between the device and the secure network. Instead of directly using PSKs for authentication, the system uses device identifiers as intermediaries to verify device legitimacy, adding a layer of security that prevents unauthorized access even if PSKs are compromised.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If stolen devices can access secure networks, then ease of operation is improved for legitimate users, but unauthorized access risk increases

Engineering Contradiction:
Improvedevice access convenienceVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the network continuously verifies device identifiers against registered identifiers before granting access. This feedback loop ensures that only authenticated devices can access the network, providing real-time verification that prevents unauthorized access while maintaining ease of operation for legitimate devices.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary authentication by registering device identifiers before the devices need to access the secure network. This preliminary action creates an authorization database that enables rapid verification of device legitimacy, allowing legitimate users to access the network easily while blocking unauthorized devices.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If PSKs are stored in communication devices, then authentication capability is improved, but security vulnerability increases when devices are stolen or compromised

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication verification function from the device itself and relocates it to the network side. Instead of relying on PSKs stored in the device for authentication, the system extracts the authentication capability by comparing device identifiers against registered identifiers in the network, removing the security vulnerability associated with storing authentication credentials in potentially compromised devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10764267B2Device registration via authentication transference
Publication Date: 2020.09.01 MOTOROLA SOLUTIONS INC
  • US10764267B2 patent drawing
  • US10764267B2 patent drawing
  • US10764267B2 patent drawing

AI summary

A method and system for authenticating a communication device with an application server. The application server includes a gateway registration port, a gateway server port, and an electronic processor. The electronic processor is configured to receive, via the gateway registration port, a registration request, including a unique identifier, from a first device over a first communications network that operates in accordance with a first modality and receive, at the gateway server port, an access request including an identifier from an unknown device over a second communications network that operates in accordance with a second modality. The electronic processor is configured to compare the second identifier with the first identifier to determine if the identifiers match, grant the unknown device access when the identifiers match, and deny the unknown device access when the identifiers do not match.