Pre-Shared Key Authentication With Encrypted Identity Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity authentication methods in communication networks expose sensitive entity information during authentication, risking privacy and security, and are vulnerable to quantum computing and dictionary brute force attacks.

Innovation Solution

Implement a pre-shared key-based identity authentication method where identity information is encrypted as ciphertext, using a message encryption key to ensure confidentiality and resist quantum computing and dictionary attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If pre-shared key authentication is used, then authentication efficiency is improved, but identity information is exposed during transmission

Engineering Contradiction:
Improveauthentication efficiencyVSAvoididentity information exposure
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent introduces an intermediary encryption mechanism where identity information is encrypted before transmission. A temporary public key pair is generated for each authentication session, and the identity information is encrypted using the temporary public key. This intermediary encryption layer prevents direct exposure of identity information while maintaining authentication efficiency through the pre-shared key mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into distinct phases: key generation, identity information encryption, transmission, and verification. The identity information is separated from the authentication key and encrypted independently, allowing efficient authentication while protecting identity data. The segmentation enables the system to maintain high authentication efficiency while preventing information exposure.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If identity information is transmitted in plain text, then authentication process is simplified, but sensitivity and security are reduced

Engineering Contradiction:
Improveauthentication process complexityVSAvoidsecurity vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the parameter of identity information from plain text to encrypted ciphertext. The identity information is transformed through encryption algorithms, changing its state from vulnerable to protected. This parameter change maintains authentication functionality while eliminating the harmful exposure of sensitive data, balancing simplicity with security.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent converts the potential harm of exposed identity information into a benefit by using encryption. The encryption mechanism, which adds complexity to the transmission process, actually protects the identity information from attackers. The apparent complexity of encryption is transformed into a security advantage, converting a potential weakness into a strength.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Ease of manufacture

If traditional authentication mechanisms are used, then implementation is straightforward, but resistance to quantum computing and dictionary attacks is insufficient

Engineering Contradiction:
Improveimplementation easeVSAvoidresistance to quantum and dictionary attacks
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent performs preliminary key generation and encryption setup before the actual authentication occurs. Temporary public key pairs are generated in advance, and encryption mechanisms are prepared beforehand. This preliminary action ensures that when authentication occurs, the system can quickly and reliably resist quantum computing and dictionary attacks without adding complexity to the main authentication flow.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses a composite authentication mechanism combining pre-shared keys with temporary public key encryption. This composite approach integrates multiple security layers: the pre-shared key provides efficient authentication, while the temporary public key encryption provides protection against quantum and dictionary attacks. The combination maintains implementation ease while significantly enhancing security reliability.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS12537669B2Identity authentication method and apparatus, storage medium, program, and program product
Publication Date: 2026.01.27 CHINA IWNCOMM
  • US12537669B2 patent drawing
  • US12537669B2 patent drawing
  • US12537669B2 patent drawing

AI summary

An identity authentication method is disclosed in embodiments of the present application. When a requester and an authentication access controller perform identity authentication using an authentication mechanism of a pre-shared key, the identity information of entities is transmitted in the form of ciphertext, thereby preventing the identity information of the entities from being exposed during the transmission, so that attackers cannot obtain private or sensitive information. The mutual or unilateral identity authentication between the authentication access controller and the requester is achieved while ensuring the confidentiality of the entity identity and related information, thereby laying a foundation for ensuring that the user accessing the network is legitimate and/or the network accessed by the user is legitimate. Meanwhile, in connection with key exchange calculations and by an ingenious and detailed design, the ability of the authentication process to resist dictionary brute force attacks or quantum computing attacks is enhanced. Further disclosed in embodiments of the present application are an identity authentication apparatus, a storage medium, a program, and a program product.