Endpoint Authentication via Cryptographic Security Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for communication endpoints with secure memory devices in networks lack robustness against counterfeit, tampering, and unauthorized access, particularly in ensuring the integrity and authenticity of data and devices.

Innovation Solution

Implementing a security server and memory devices with integrated security features that utilize cryptographic computations to validate the identity of memory devices, generate secret cryptographic keys, and control access, thereby eliminating the need for physical SIM cards and enhancing security through centralized security implementations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current authentication methods are used for communication endpoints, then device compatibility and ease of operation are maintained, but security robustness against counterfeit and tampering deteriorates

Engineering Contradiction:
Improvesecurity robustnessVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security server as an intermediary between endpoints and service providers. This centralized security infrastructure mediates authentication by validating cryptographic proofs and managing security credentials, thereby enhancing security robustness without requiring complex authentication logic in each endpoint device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces physical SIM cards with cryptographic authentication mechanisms. Instead of relying on physical card insertion and contact-based authentication, the system uses cryptographic keys, digital signatures, and secure enclave computations to authenticate endpoints, thereby improving security against counterfeit while reducing mechanical complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If physical SIM cards are used for authentication, then device operation is simplified, but security against unauthorized access and tampering deteriorates

Engineering Contradiction:
Improveprotection against unauthorized accessVSAvoidauthentication operation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent substitutes physical SIM card mechanisms with cryptographic authentication. Endpoints use secure enclaves to generate and verify cryptographic proofs of identity and integrity, eliminating the need for physical card handling while providing stronger protection against unauthorized access and tampering.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent uses cryptographic copies of security credentials stored in secure enclaves rather than physical SIM cards. These cryptographic representations (keys, certificates, signed proofs) serve as digital copies that provide enhanced security while maintaining operational functionality through software-based authentication protocols.

Inventive Principle:
Principle #26Copying

3Reliability

If decentralized security implementations are used in devices, then device autonomy is maintained, but security consistency and reliability deteriorate

Engineering Contradiction:
Improvesecurity consistencyVSAvoidcentralized security infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized security server as an intermediary that ensures security consistency across all endpoints. This server validates cryptographic proofs, manages security credentials, and enforces authentication policies uniformly, thereby achieving security consistency without requiring complex decentralized security implementations in each device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal security infrastructure that serves multiple endpoints through a single centralized security server. This multi-functional system handles authentication, authorization, credential management, and security validation for various service providers and endpoints, achieving security consistency through standardized centralized processes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of manufacture

If physical SIM cards are required for service access, then service authentication is simplified, but device manufacturing complexity and cost increase

Engineering Contradiction:
Improvedevice manufacturing simplicityVSAvoidservice access requirement
Core Design Contradiction:
Ease of manufactureVSEase of operation

Solution Approach 1:

The patent replaces physical SIM card requirements with cryptographic authentication mechanisms embedded in secure enclaves. This substitution eliminates the need for physical card slots, SIM card handling, and associated mechanical components during device manufacturing, thereby simplifying manufacturing while maintaining service access functionality through software-based authentication.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11811743B2Online service store for endpoints
Publication Date: 2023.11.07 MICRON TECHNOLOGY INC
  • US11811743B2 patent drawing
  • US11811743B2 patent drawing
  • US11811743B2 patent drawing

AI summary

An online service store to configure services for endpoints in connection with validating authenticity of the endpoints. For example, a service can be ordered for an endpoint prior to the use of the endpoint. After receiving a request having identity data generated by a memory device configured in the endpoint, a server system can determine, based on a secret of the memory device and other data stored about the endpoint, the validity of the identity data and thus the authenticity of the endpoint. Based on the service ordered for the endpoint, the server system causes the endpoint to be connected to a client server to receive the service. The server system can cause the firmware of the endpoint to be updated to enable the endpoint to receive the service from the client server.