Display-Authenticated Security Association Protocol

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure communication protocols in wireless networks, such as Diffie-Hellman key exchanges, are vulnerable to man-in-the-middle attacks, where a third party can impersonate both communicating parties, leading to security breaches and authentication issues, especially in low-power networks like body area networks.

Innovation Solution

The implementation of a display-authenticated security association protocol that uses public keys to generate and display a shared secret, allowing legitimate parties to verify each other's identity through matching display values, preventing computational forgery by third parties, and establishing a secure shared master key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If Diffie-Hellman key exchange is used to establish shared secrets over open channels, then two parties can securely exchange information without pre-shared secrets, but the system becomes vulnerable to man-in-the-middle attacks where a third party can impersonate both parties

Engineering Contradiction:
Improvekey exchange convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a new dimension of authentication by displaying visual representations of public keys or derived values on the user interfaces of both devices. This additional visual verification layer allows users to confirm that they are communicating with the intended party, thereby preventing man-in-the-middle attacks while maintaining the convenience of key exchange over open channels.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent uses the user interface display as an intermediary verification mechanism. Instead of relying solely on cryptographic protocols, the system introduces a human-in-the-loop verification step where users visually confirm matching displayed values, serving as a mediator to authenticate the communication parties before finalizing the key exchange.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If pre-shared passwords are used for authentication, then parties can verify each other's identity, but the password may be exposed to third parties through compromised central controllers or unintended human behavior

Engineering Contradiction:
Improveauthentication capabilityVSAvoidpassword exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication verification from the centralized password storage system and distributes it to the individual devices through public key cryptography. Each device generates and displays its own authentication value locally, eliminating the need to store or transmit sensitive passwords through vulnerable central controllers, thereby preventing password exposure while maintaining authentication capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces the mechanical password-based authentication system with a cryptographic public key system. Instead of relying on secret shared passwords that must be stored and transmitted, the system uses public key cryptography where devices exchange public information and derive shared secrets, substituting the vulnerable password mechanism with a more secure cryptographic approach.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If manual installation of pre-shared keys is performed, then secure communication can be established, but the process becomes inconvenient and difficult to reinstall when needed

Engineering Contradiction:
Improvesecure communicationVSAvoidkey installation convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent performs preliminary key pair generation and public key exchange automatically during the initial device pairing process. The systems pre-compute and exchange necessary cryptographic materials, and store them securely for future use. This preliminary setup eliminates the need for manual key installation and reinstallation, as the automatic key management system handles subsequent authentication using the pre-established cryptographic materials.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service key management where devices automatically generate, exchange, store, and manage their own cryptographic key pairs without human intervention. The system autonomously handles key installation, renewal, and replacement, eliminating the inconvenience of manual key management while maintaining secure communication through cryptographic protection.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8644515B2Display authenticated security association
Publication Date: 2014.02.04 TEXAS INSTRUMENTS INC
  • US8644515B2 patent drawing
  • US8644515B2 patent drawing
  • US8644515B2 patent drawing

AI summary

A system and method for establishing a mutual entity authentication and a shared secret between two devices using displayed values on each device. Unique first private keys and first public keys are assigned to both devices. The public keys are exchanged between the two devices. Both devices compute a shared secret from their own private keys and the received public keys. Both devices compute, exchange, and verify their key authentication codes of the shared secret. If verification is successful, both devices use the shared secret to generate a displayed value. One or more users compare the displayed values and provide an indication to the devices verifying whether the displays match. If the displays match, then the devices compute a shared master key, which is used either directly or via a later-generated session key for securing message communications between the two devices.