Authentication Access Controller With Encrypted Certificate Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In communication networks, identity authentication of REQuesters poses a security risk due to the interception of sensitive information like digital certificates, which can compromise the authentication access controller, the REQuester, and the network.
Innovation Solution
A method involving an authentication access controller that encrypts identity information using a message encryption secret key, decrypts it to obtain a digital certificate, and verifies it through a trusted authentication server, ensuring confidentiality and authenticity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If identity information is transmitted in plaintext for authentication, then authentication can be performed, but sensitive information is exposed to interception risks
Solution Approach 1:
The patent introduces a trusted third-party authentication server as an intermediary to handle the verification of digital certificates. The REQuester's identity information is encrypted and sent to this mediator, which then verifies the certificate without the authentication access controller directly handling the sensitive plaintext identity information, thus reducing interception risks while maintaining authentication reliability
Solution Approach 2:
The patent extracts the sensitive identity verification function from the authentication access controller and delegates it to a specialized authentication server. The authentication access controller only handles the encrypted identity information and receives verification results, separating the handling of sensitive data from the authentication decision-making process
2Reliability
If digital certificates are used for identity authentication, then identity verification is achieved, but private information like ID numbers and bank card information is exposed
Solution Approach 1:
The authentication server acts as a trusted intermediary that holds and verifies the digital certificates. The authentication access controller never directly accesses or processes the plaintext identity information contained in the certificates, as all verification operations are performed by the intermediary authentication server, thus protecting privacy while maintaining verification capability
Solution Approach 2:
The patent uses digital certificates as cryptographic copies of identity information that can be verified without exposing the original sensitive data. The digital certificate serves as a verifiable copy that proves identity without revealing private information like ID numbers and bank card details
Data Source
AI summary
A method and device for identity authentication. An authentication access controller (AAC) acquires an identity ciphertext message transmitted by a requesting device (REQ), the identity ciphertext message comprising an identity information ciphertext of the REQ, the AAC decrypts the identity information ciphertext of the REQ to generate a digital certificate (CertREQ) of the REQ, transmits a first authentication request message comprising the CertREQ to a first authentication server, and receives a first authentication response message transmitted by the first authentication server, the first authentication response message comprising authentication result information and a digital signature of the first authentication server, the AAC utilizes a public key of the first authentication server to verify the digital signature of the first authentication server, and if successfully verified, then the AAC determines an identity authentication result for the REQ on the basis of the verification result of the CertREQ in the authentication result information.


