Display-Authenticated Security Association Protocol
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure communication protocols in wireless networks, such as Diffie-Hellman key exchanges, are vulnerable to man-in-the-middle attacks, where a third party can impersonate both communicating parties, leading to security breaches and authentication issues, especially in low-power networks like body area networks.
Innovation Solution
The implementation of a display-authenticated security association protocol that uses public keys to generate and display a shared secret, allowing legitimate parties to verify each other's identity through matching display values, preventing computational forgery by third parties, and establishing a secure shared master key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If Diffie-Hellman key exchange is used to establish shared secrets over open channels, then two parties can securely exchange information without pre-shared secrets, but the system becomes vulnerable to man-in-the-middle attacks where a third party can impersonate both parties
Solution Approach 1:
The patent introduces a new dimension of authentication by displaying visual representations of public keys or derived values on the user interfaces of both devices. This additional visual verification layer allows users to confirm that they are communicating with the intended party, thereby preventing man-in-the-middle attacks while maintaining the convenience of key exchange over open channels.
Solution Approach 2:
The patent uses the user interface display as an intermediary verification mechanism. Instead of relying solely on cryptographic protocols, the system introduces a human-in-the-loop verification step where users visually confirm matching displayed values, serving as a mediator to authenticate the communication parties before finalizing the key exchange.
2Reliability
If pre-shared passwords are used for authentication, then parties can verify each other's identity, but the password may be exposed to third parties through compromised central controllers or unintended human behavior
Solution Approach 1:
The patent extracts the authentication verification from the centralized password storage system and distributes it to the individual devices through public key cryptography. Each device generates and displays its own authentication value locally, eliminating the need to store or transmit sensitive passwords through vulnerable central controllers, thereby preventing password exposure while maintaining authentication capability.
Solution Approach 2:
The patent replaces the mechanical password-based authentication system with a cryptographic public key system. Instead of relying on secret shared passwords that must be stored and transmitted, the system uses public key cryptography where devices exchange public information and derive shared secrets, substituting the vulnerable password mechanism with a more secure cryptographic approach.
3Reliability
If manual installation of pre-shared keys is performed, then secure communication can be established, but the process becomes inconvenient and difficult to reinstall when needed
Solution Approach 1:
The patent performs preliminary key pair generation and public key exchange automatically during the initial device pairing process. The systems pre-compute and exchange necessary cryptographic materials, and store them securely for future use. This preliminary setup eliminates the need for manual key installation and reinstallation, as the automatic key management system handles subsequent authentication using the pre-established cryptographic materials.
Solution Approach 2:
The patent implements self-service key management where devices automatically generate, exchange, store, and manage their own cryptographic key pairs without human intervention. The system autonomously handles key installation, renewal, and replacement, eliminating the inconvenience of manual key management while maintaining secure communication through cryptographic protection.
Data Source
AI summary
A system and method for establishing a mutual entity authentication and a shared secret between two devices using displayed values on each device. Unique first private keys and first public keys are assigned to both devices. The public keys are exchanged between the two devices. Both devices compute a shared secret from their own private keys and the received public keys. Both devices compute, exchange, and verify their key authentication codes of the shared secret. If verification is successful, both devices use the shared secret to generate a displayed value. One or more users compare the displayed values and provide an indication to the devices verifying whether the displays match. If the displays match, then the devices compute a shared master key, which is used either directly or via a later-generated session key for securing message communications between the two devices.


