Dynamic Identity Generation for Secure Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure identity devices require time-consuming and costly procedures for unique network address assignment and multiple identity programming, which is inefficient and vulnerable to unauthorized access, especially when physical interfaces are not used or identities are not known at the time of manufacture.

Innovation Solution

A multiple-identity secure device with a persistently-stored seed identity and a transformation engine that dynamically generates unique identities using predefined logic, allowing for real-time identity generation and support of multiple identities without the need for physical interfaces or pre-known identities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If unique network addresses are assigned during manufacture or field programming, then device identity is established, but the process is time-consuming and costly

Engineering Contradiction:
Improvedevice identity establishmentVSAvoidaddress assignment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

A seed identity is pre-stored in secure memory during manufacture, serving as the foundation for generating multiple unique identities. This preliminary action eliminates the need for time-consuming field programming of complete identities, as the seed identity can be rapidly transformed into any required unique identity on-demand.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The device includes a transformation engine that automatically generates unique identities from the seed identity without requiring external programming equipment or manual intervention. This self-service capability allows the device to autonomously establish its identity as needed, eliminating dependency on costly field programming operations.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If multiple identities are programmed into the device, then multiple identities are supported, but device complexity and memory requirements increase

Engineering Contradiction:
Improvemultiple identity supportVSAvoididentity storage structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Instead of storing multiple complete identities in memory, the system stores a single seed identity that serves as a template. The transformation engine generates copies of unique identities from this seed when needed, following predefined logic. This approach supports multiple identities while minimizing memory requirements and device complexity.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The seed identity serves multiple functions: it acts as a unique device identifier, a cryptographic key, and a template for generating multiple operational identities. This multi-functionality eliminates the need for separate storage of multiple identities, reducing device complexity while maintaining adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If physical interfaces are used for identity card exchange, then identity changes are enabled, but security vulnerabilities increase

Engineering Contradiction:
Improveidentity exchange capabilityVSAvoidunauthorized access vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system replaces physical identity card interfaces with a software-based transformation engine that generates identities from the seed identity stored in secure memory. This substitution eliminates mechanical interfaces that are vulnerable to physical tampering, unauthorized card swapping, and cloning attacks, while maintaining the ability to exchange identities through secure software operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Ease of manufacture

If identities are assigned at manufacture, then deployment is simplified, but flexibility for unknown identities is lost

Engineering Contradiction:
Improveidentity assignment processVSAvoididentity flexibility
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The system transitions from static identity assignment to dynamic identity generation. The seed identity remains constant and is stored during manufacture, but the transformation engine can generate any number of unique identities from it based on predefined logic. This dynamic approach maintains ease of manufacture while providing flexibility to adapt to different deployment scenarios and unknown identity requirements.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11895351B2System and method for supporting multiple identities for a secure identity device
Publication Date: 2024.02.06 COMCAST CABLE COMM LLC
  • US11895351B2 patent drawing
  • US11895351B2 patent drawing
  • US11895351B2 patent drawing

AI summary

A multiple-identity secure device (MISD) persistently may store an identification code. The identification code may be stored in an integral memory of the device, or on an interchangeable card received in a physical interface of the MISD. The MISD may generate one or more unique identities (e.g., network addresses) from the stored identification code. The generated identities may be dynamically generated or may be securely stored in the MISD for subsequent retrieval. The generated identities may generate in accordance with an addressing scheme, a global/network setting, or as determined from a received data transmission.