Digital Key Sharing via Primary Device Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing use of digital keys in the automobile industry for vehicle access and sharing raises security concerns, particularly with regards to hacking and the need for efficient authentication and account management in communication systems.
Innovation Solution
A method and apparatus for securely sharing and managing digital keys in a communication system, where a primary device authenticates a secondary device without requiring it to register an account at a server, enhancing authentication and reliability through a trusted execution environment and secure key sharing protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a secondary device registers an account at a server to obtain a digital key, then the key server can manage and provide the digital key, but the system complexity and security risks increase due to account management and server exposure to hacking
Solution Approach 1:
The patent extracts the account management function from the key server by introducing a primary device that handles authentication and key distribution. The secondary device obtains the digital key through the primary device without needing to register at the key server, thereby removing the vulnerable account management layer while maintaining key distribution capability
Solution Approach 2:
The primary device serves as an intermediary between the key server and secondary devices. It authenticates the secondary device and obtains the digital key on its behalf, eliminating the need for secondary devices to directly interact with the key server and its account management system
2Ease of operation
If a secondary device directly requests a digital key from a key server, then the key providing process is straightforward, but security concerns arise due to potential hacking and lack of trusted authentication
Solution Approach 1:
The primary device performs preliminary authentication of the secondary device before the key request is made to the key server. This pre-validation ensures that only authorized devices can obtain digital keys, adding a security layer without complicating the overall process for end users
3Reliability
If multiple accounts are managed at the key server for different devices, then each device can be individually authenticated, but the management overhead and potential attack surface increase
Solution Approach 1:
The patent merges the authentication functions for multiple secondary devices into a single primary device account. The primary device can authenticate and obtain digital keys for multiple secondary devices, eliminating the need for separate account registrations at the key server while maintaining individual device authentication through the primary device's validation
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
The present disclosure relates to a sensor network, machine type communication (MTC), machine-to-machine (M2M) communication, and technology for internet of things (IoT). An apparatus and method are provided for providing and managing security information in a communication system. A method of a first device includes detecting that a second device requests to share security information of the first device; registering information of the second device at a service provider; receiving, from the service provider, authentication information for the second device to share the security information of the first device; and transmitting the authentication information to the second device.