Group Registration Protocol for Secure Multi-Device Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing registration protocols do not provide a mechanism for multiple clients to securely access one system in a secure and efficient manner, lacking a 'reverse single sign-on' capability.

Innovation Solution

A method for registering a group of communication devices in a communication network using a single registration procedure, where a group challenge message is sent to the devices, and responses are aggregated to authenticate the group with an authenticator, allowing each device to establish a unique data session.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional registration protocols are used for multiple clients to access one system, then each client can be authenticated individually, but the registration process becomes inefficient and signaling overhead increases

Engineering Contradiction:
Improveregistration efficiencyVSAvoidsignaling overhead
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent combines multiple individual client authentication processes into a single group registration procedure. The network device sends one group challenge message to multiple clients simultaneously, and aggregates their responses into a single authentication process, reducing signaling overhead and improving registration efficiency for multiple clients accessing one system

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The group challenge message and authentication mechanism serve multiple clients simultaneously, making the registration system universal. A single authentication procedure handles multiple clients, and the aggregated response mechanism allows the system to verify multiple clients' credentials through one unified process, reducing the need for separate authentication transactions

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If a single registration procedure is used for multiple clients, then signaling overhead is reduced, but ensuring unique session keys for each client becomes more complex

Engineering Contradiction:
Improvesignaling overheadVSAvoidunique session key generation
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

While using a single group challenge message for all clients, the patent ensures each client receives a unique session key through local key derivation. Each client computes a unique session key based on the group challenge and their individual credentials, maintaining security and uniqueness at the local level while benefiting from centralized authentication

Inventive Principle:
Principle #3Local quality

3Ease of operation

If traditional authentication protocols are used, then each client can be authenticated separately, but the process lacks efficiency for group access scenarios

Engineering Contradiction:
Improvegroup access capabilityVSAvoidauthentication time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent merges multiple separate authentication operations into a single parallel process. The network device sends one group challenge to multiple clients simultaneously and aggregates their responses, allowing concurrent authentication of multiple clients and significantly reducing total authentication time compared to sequential processing

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2580901B1Secure registration of group of clients using single registration procedure
Publication Date: 2020.04.22 THALES DIS FRANCE SA
  • EP2580901B1 patent drawingFigure 1
  • EP2580901B1 patent drawingFigure 2
  • EP2580901B1 patent drawingFigure 3

AI summary

Automated secure registration techniques for communication devices are provided which address the problem of allowing multiple clients to gain access to one system, and thus provide a solution to the "reverse single sign-on" problem. For example, a method for registering a group of two or more communication devices in a communication network comprises the following steps. A group challenge message is sent from a network device to the group of two or more communication devices. The network device receives one or more response messages to the group challenge respectively from one or more of the group of two or more communication devices, wherein the response message from each of the responding communication devices in the group comprises a group credential corresponding to the group.