Dynamic Multi-Device Authentication via Group Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication methods are cumbersome, inefficient, and prone to unauthorized access as the number of devices and applications requiring authentication increases, leading to inefficiencies and security vulnerabilities.
Innovation Solution
A dynamic multi-device authentication system that generates an encryption key pair and cross-reference data, allowing devices to authenticate each other through a network, reducing data transmission and enhancing security by using a reference key and hop sequences to generate and compare authentication codes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If conventional authentication methods are used for each device individually, then security can be maintained per device, but the authentication process becomes cumbersome and inefficient as the number of devices increases
Solution Approach 1:
The patent combines multiple device authentications into a single group authentication process. By creating a group credential that represents multiple devices, the system allows one authentication event to validate all devices in the group simultaneously, eliminating the need for individual authentication of each device and significantly improving efficiency as device count increases
Solution Approach 2:
The group credential serves multiple functions: it authenticates all devices in the group, provides a single point of management for multiple devices, and enables streamlined access control. This multi-functional approach allows the same authentication mechanism to handle both individual and group-based access requirements
2Reliability
If more devices are authenticated individually, then comprehensive access control is achieved, but the system becomes more susceptible to unauthorized activity and security vulnerabilities
Solution Approach 1:
By merging authentication credentials at the group level, the system reduces the attack surface. Instead of multiple individual credentials that could each be compromised, the system uses a single group credential that provides unified security management, making the system more resilient to unauthorized access attempts
Solution Approach 2:
The group credential acts as an intermediary between individual devices and the authentication system. This intermediary layer provides centralized security management and reduces direct exposure of individual device credentials, thereby enhancing security while simplifying the authentication architecture
3Adaptability or versatility
If authentication data is stored for each device separately, then device-specific authentication is possible, but data storage and transmission requirements increase significantly
Solution Approach 1:
The patent merges authentication data into a consolidated group credential structure. Instead of storing separate authentication data for each device, the system stores a single group credential that represents multiple devices, dramatically reducing data storage requirements and transmission overhead while maintaining the ability to manage device-specific authentication needs
Data Source
AI summary
Arrangements for dynamically authenticating multiple devices in a key network are provided. In some examples, registration information associated with a plurality of devices in a key network may be received. The registration information may include device attributes. Device keys including cross reference data may be generated and transmitted to the plurality of devices. A reference key including one or more starting points for executing one or more hop sequences based on generated hop counts in the reference key may be generated. A first authentication code may also be generated and a hash value of the first authentication code may be stored. Upon receiving a request for authentication, the reference key may be transmitted to the requesting device. The hop sequence(s) may then be executed by one or more of the computing devices in the key network to generate a comparison authentication code. The comparison authentication code may be compared to the first authentication code to determine whether the device(s) may be authenticated.


