Edge Gateway Ad-Hoc Link Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for establishing ad-hoc communication links between communication devices, such as in vehicle-to-vehicle or vehicle-to-everything communications, are too slow due to complex authentication procedures, which are not suitable for real-time critical applications like 5G networks.

Innovation Solution

An edge computing gateway facilitates fast authentication of ad-hoc communication links by generating and transmitting cryptographic keys to communication devices, enabling secure communication without the need for further involvement, using either symmetric or asymmetric key exchange methods, and supporting real-time authentication within a defined area.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If typical Challenge-Response-Authentication scenarios are used, then security is ensured, but authentication speed deteriorates due to complex messaging, verification and calculation procedures

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent applies preliminary action by pre-establishing cryptographic key pairs (public key and private key) for each communication device before ad-hoc communication is needed. When ad-hoc communication is required, devices can immediately exchange public keys and derive session keys without performing complex authentication procedures at that moment, thus achieving fast authentication while maintaining security through pre-configured cryptographic credentials

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the complex verification and calculation procedures from the real-time authentication process and moves them to a preliminary setup phase. By separating key generation from key exchange, the patent removes the computational burden from the actual authentication moment, allowing devices to simply exchange public keys and derive session keys without complex messaging and verification procedures

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If ad-hoc communication links are established between unknown devices, then communication flexibility is improved, but authentication complexity increases due to lack of pre-existing trust relationships

Engineering Contradiction:
Improvecommunication flexibilityVSAvoidauthentication complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent uses public key cryptography as an intermediary mechanism that enables trust establishment between unknown devices. Each device generates its own key pair and shares only the public key with communication partners, while retaining the private key securely. This intermediary public key system allows any device to authenticate any other device without requiring pre-existing trust relationships or complex mutual authentication protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies self-service by enabling each communication device to independently generate its own cryptographic key pair and manage its own authentication credentials. Devices autonomously derive session keys from exchanged public keys using the Diffie-Hellman key agreement method, without requiring external authentication servers or complex multi-party verification procedures, thus simplifying the authentication process while maintaining security

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3713152B1Techniques for authenticating establishment of an ad-hoc communication link
Publication Date: 2024.09.25 DEUTSCHE TELEKOM AG
  • EP3713152B1 patent drawingFigure 1
  • EP3713152B1 patent drawingFigure 2
  • EP3713152B1 patent drawingFigure 3

AI summary

The disclosure relates to an edge computing gateway (110) for authenticating establishment of an ad-hoc communication link(104) between at least two communication devices (101, 102, 103), in particular cars, in a communication network (120), in particular a 5G communication network, the edge computing gateway (110) comprising: a communication interface (301) configured to communicate over respective communication links (111, 112, 113) with the at least two communication devices (101, 102, 103); a processor (302) configured to authenticate the at least two communication devices (101, 102, 103) over the respective communication links (111, 112, 113) based on an authentication procedure that meets real-time requirements with respect to communication latency; and a key generator (303) configured to generate a cryptographic key associated with the at least two communication devices (101, 102, 103); wherein the communication interface (301) is configured to transmit the cryptographic key to a respective communication device of the at least two communication devices (101, 102, 103) in response to the authentication of the respective communication device.