Pre-Shared Key Authentication With Encrypted Identity Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identity authentication methods in communication networks expose sensitive entity information during authentication, risking privacy and security, and are vulnerable to quantum computing and dictionary brute force attacks.
Innovation Solution
Implement a pre-shared key-based identity authentication method where identity information is encrypted as ciphertext, using a message encryption key to ensure confidentiality and resist quantum computing and dictionary attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If pre-shared key authentication is used, then authentication efficiency is improved, but identity information is exposed during transmission
Solution Approach 1:
The patent introduces an intermediary encryption mechanism where identity information is encrypted before transmission. A temporary public key pair is generated for each authentication session, and the identity information is encrypted using the temporary public key. This intermediary encryption layer prevents direct exposure of identity information while maintaining authentication efficiency through the pre-shared key mechanism.
Solution Approach 2:
The authentication process is segmented into distinct phases: key generation, identity information encryption, transmission, and verification. The identity information is separated from the authentication key and encrypted independently, allowing efficient authentication while protecting identity data. The segmentation enables the system to maintain high authentication efficiency while preventing information exposure.
2Device complexity
If identity information is transmitted in plain text, then authentication process is simplified, but sensitivity and security are reduced
Solution Approach 1:
The patent changes the parameter of identity information from plain text to encrypted ciphertext. The identity information is transformed through encryption algorithms, changing its state from vulnerable to protected. This parameter change maintains authentication functionality while eliminating the harmful exposure of sensitive data, balancing simplicity with security.
Solution Approach 2:
The patent converts the potential harm of exposed identity information into a benefit by using encryption. The encryption mechanism, which adds complexity to the transmission process, actually protects the identity information from attackers. The apparent complexity of encryption is transformed into a security advantage, converting a potential weakness into a strength.
3Ease of manufacture
If traditional authentication mechanisms are used, then implementation is straightforward, but resistance to quantum computing and dictionary attacks is insufficient
Solution Approach 1:
The patent performs preliminary key generation and encryption setup before the actual authentication occurs. Temporary public key pairs are generated in advance, and encryption mechanisms are prepared beforehand. This preliminary action ensures that when authentication occurs, the system can quickly and reliably resist quantum computing and dictionary attacks without adding complexity to the main authentication flow.
Solution Approach 2:
The patent uses a composite authentication mechanism combining pre-shared keys with temporary public key encryption. This composite approach integrates multiple security layers: the pre-shared key provides efficient authentication, while the temporary public key encryption provides protection against quantum and dictionary attacks. The combination maintains implementation ease while significantly enhancing security reliability.
Data Source
AI summary
An identity authentication method is disclosed in embodiments of the present application. When a requester and an authentication access controller perform identity authentication using an authentication mechanism of a pre-shared key, the identity information of entities is transmitted in the form of ciphertext, thereby preventing the identity information of the entities from being exposed during the transmission, so that attackers cannot obtain private or sensitive information. The mutual or unilateral identity authentication between the authentication access controller and the requester is achieved while ensuring the confidentiality of the entity identity and related information, thereby laying a foundation for ensuring that the user accessing the network is legitimate and/or the network accessed by the user is legitimate. Meanwhile, in connection with key exchange calculations and by an ingenious and detailed design, the ability of the authentication process to resist dictionary brute force attacks or quantum computing attacks is enhanced. Further disclosed in embodiments of the present application are an identity authentication apparatus, a storage medium, a program, and a program product.


