Secure Domain Key Distribution for WHDI Device Registration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless Home Digital Interface (WHDI) networks lack effective security procedures to maintain user privacy and prevent unauthorized devices from joining the network, as conventional wireless technologies are vulnerable to unauthorized access.

Innovation Solution

A secure and efficient method for device registration in WHDI networks is implemented, using Personal Identification Numbers (PINs) to generate device registration keys and distribute domain keys, ensuring only authorized devices can connect and share content, through a process involving PIN generation, certificate validation, and secure key exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional wireless technologies are used for device connectivity, then wireless communication capability is achieved, but security vulnerability to unauthorized access occurs

Engineering Contradiction:
Improvewireless communication capabilityVSAvoidsecurity against unauthorized access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary security actions by establishing domain keys and registration procedures before devices connect to the wireless network. The system pre-configures security credentials and authentication mechanisms, so that when unauthorized access attempts occur, the preliminary security framework is already in place to reject them. This is evident in the domain key distribution method where registration keys are established beforehand through secure key encapsulation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces domain keys and registration authorities as intermediary security elements between devices and the wireless network. Rather than direct device-to-device connectivity, all communication is mediated through authenticated domain keys that verify device legitimacy. The registration authority acts as an intermediary that issues and manages these domain keys, creating a trusted intermediary layer that prevents unauthorized access while maintaining wireless connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If device identity is made visible for network discovery, then device discoverability is improved, but user privacy and device security are compromised

Engineering Contradiction:
Improvedevice discoverabilityVSAvoiduser privacy
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent applies local quality by implementing different visibility levels for different devices and information types within the network. Authorized devices within the domain can discover and communicate with each other using their identifiers, while unauthorized external devices cannot obtain or use these identifiers. The domain key system creates local visibility permissions where device identities are visible only to authorized members of the domain, not to the entire wireless network.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements preliminary anti-action by pre-establishing domain keys and authentication credentials that prevent unauthorized devices from discovering or accessing network devices. The registration system proactively secures device identities by binding them to authenticated domain keys before any network discovery or communication attempts occur. This preliminary security measure counteracts potential privacy violations before they can happen.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP2382735B1Secure and efficient domain key distribution for device registration
Publication Date: 2018.05.09 GOOGLE TECHNOLOGY HOLDINGS LLC
  • EP2382735B1 patent drawingFigure 1
  • EP2382735B1 patent drawingFigure 2
  • EP2382735B1 patent drawingFigure 3A

AI summary

A domain key is securely distributed from a device in an existing network to a device outside the network. Each device generates the session key on its own using the first random number, the second random number, the Personal Identification Number, and the same key generation function. The device in the existing network sends the domain key encrypted with the session key to the other device.