Digital Key Provisioning via Server-Mediated Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital key technologies face security concerns due to the exposure of digital keys integrated with electronic devices, making them vulnerable to malicious use such as hacking.

Innovation Solution

An electronic device equipped with a communication unit, memory for digital key provisioning programs, and a processor that performs device authentication, identifies digital key service access rights through a server, and generates and stores digital keys in response to user requests, ensuring secure key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If digital key is integrated into mobile device using wireless communication technology, then user convenience is improved by eliminating physical keys, but security risk increases due to vulnerability to hacking and malicious use

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication process into multiple independent stages: device authentication, user authentication, and digital key generation. Each stage verifies specific credentials and permissions, preventing single-point compromise. The digital key is separated from the mobile device itself and stored in a secure element, creating logical segmentation between the communication interface and the cryptographic credentials.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a server as an intermediary between the mobile device and the target device. The server acts as a trusted mediator that issues digital keys only after verifying both device authentication and user authentication. This intermediary layer prevents direct unauthorized communication between devices while maintaining user convenience through automated authentication flows.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If digital key provisioning is automated through server-based authentication, then key distribution efficiency is improved, but system complexity increases due to additional authentication layers

Engineering Contradiction:
Improvekey distribution efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements preliminary device authentication before digital key provisioning. The mobile device and target device authenticate each other using pre-shared credentials or certificates before the server issues the digital key. This preliminary action ensures that only authorized devices can receive keys, automating security verification while maintaining efficient key distribution through the server's centralized management.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3734488B1Electronic device and digital key provisioning method of electronic device
Publication Date: 2024.09.18 SAMSUNG ELECTRONICS CO LTD
  • EP3734488B1 patent drawingFigure 1
  • EP3734488B1 patent drawingFigure 2
  • EP3734488B1 patent drawingFigure 3

AI summary

Disclosed are an electronic device and a method of performing digital key provisioning of an electronic device. The electronic device according to an embodiment includes a communication unit, a memory that stores programs and data for performing digital key provisioning, and a processor configured to, by executing the programs stored in the memory, perform device authentication on a target device by performing short-range communication with the target device, identify a digital key service access right of the target device through a server by obtaining user information, and control generation and storing of a digital key in response to a digital key generation request from the target device.