Dual-Certificate Authentication for Secure and Fast IoT Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication methods using two types of certificates in IoT devices lack efficiency and security, particularly with the advent of quantum computers, as they rely on current cryptography that may be vulnerable and post quantum cryptography that is slower.

Innovation Solution

A communication method and terminal that utilize two certificates, one using post quantum cryptography for security and the other using current cryptography for speed, ensuring both safety and convenience by switching between them based on need.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If post quantum cryptography is used for certificate authentication, then security against quantum computers is improved, but communication speed deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent segments the authentication process into two distinct phases: initial authentication using post quantum cryptography for security, and subsequent authentication using current cryptography for speed. This segmentation allows the system to leverage the strengths of both cryptographic methods without compromising overall security or performance

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary authentication using post quantum cryptography to establish secure communication and obtain a second certificate. This preliminary action ensures security is established first, then enables faster subsequent communications using the obtained certificate and current cryptography methods

Inventive Principle:
Principle #10Preliminary action

2Speed

If current cryptography is used for certificate authentication, then communication speed is improved, but security against quantum computers deteriorates

Engineering Contradiction:
Improvecommunication speedVSAvoidsecurity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent implements a dynamic certificate management system that transitions from post quantum cryptography in the initial phase to current cryptography in subsequent phases. This dynamic approach allows the system to adapt its cryptographic method based on the authentication stage, optimizing both security and performance

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent uses a second certificate as an intermediary that bridges the secure initial authentication phase and the faster subsequent authentication phase. This intermediary certificate enables the system to leverage current cryptography's speed benefits while maintaining the security foundation established by post quantum cryptography

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20260046117A1Communication method, communication terminal, and communication system
Publication Date: 2026.02.12 PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
  • US20260046117A1 patent drawing
  • US20260046117A1 patent drawing
  • US20260046117A1 patent drawing

AI summary

The communication method is a communication method for a communication terminal including a storage that stores a first certificate that has been given in advance, the communication method including: performing first authentication communication with a first device by using the first certificate; obtaining a second certificate through the first authentication communication, the second certificate being different from the first certificate; and performing second authentication communication with a second device by using the second certificate that has been obtained, the second device being different from the first device, wherein the first certificate stores a first public key and a first signature each generated using a first private key cryptography method, and the second certificate stores a second public key and a second signature each generated using a second private key cryptography method different from the first private key cryptography method.