Heterogeneous Network Authentication via Distributed Secret Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication protocols treat devices homogenously, ignoring their unique capabilities and features, leading to inefficient and inaccurate authentication processes by using a lowest common denominator approach.
Innovation Solution
A networked system with heterogeneous nodes, including a gateway node, secret holder nodes, and localizer nodes, that generate and combine responses based on specific capabilities, utilizing cryptographic functions and location information to create a more accurate and efficient authentication process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If authentication protocols treat all devices homogenously, then the authentication process is simplified and easier to implement, but the authentication accuracy and efficiency deteriorate because device-specific capabilities are ignored
Solution Approach 1:
The patent applies local quality by enabling each device to contribute authentication data according to its specific capabilities. Instead of treating all devices uniformly, the system allows devices with location capabilities to provide location information, devices with sensor capabilities to provide sensor data, and so forth. This ensures that each device contributes what it is best at, improving overall authentication accuracy while maintaining protocol simplicity through the standardized challenge-response framework.
2Measurement precision
If multiple devices are combined to generate authentication responses, then authentication accuracy improves by leveraging diverse capabilities, but the system complexity increases due to coordination requirements
Solution Approach 1:
The patent merges multiple device responses into a single combined authentication credential. The server issues a challenge that is distributed to multiple devices, each of which generates a response based on its capabilities. These individual responses are then combined by the server to form a comprehensive authentication decision, leveraging the strengths of each device while maintaining a unified authentication process.
Solution Approach 2:
The server acts as an intermediary that coordinates the multi-device authentication process. It distributes challenges to appropriate devices based on the authentication context, collects responses from multiple devices, and combines these responses into a final authentication decision. This intermediary role simplifies the coordination complexity by centralizing the management of the authentication workflow.
3Productivity
If device-specific capabilities are utilized in authentication, then authentication efficiency improves by leveraging unique features, but the protocol complexity increases requiring different handling for different device types
Solution Approach 1:
The patent applies dynamics by making the authentication protocol adaptive to device capabilities. The server dynamically determines which devices to involve in the authentication process based on the authentication context and device capabilities. Devices respond to challenges based on their specific capabilities, and the server dynamically combines these responses. This dynamic approach allows the protocol to efficiently leverage device-specific features without requiring rigid, complex predefined handling for each device type.
Data Source
AI summary
A disclosed example gateway node includes network communicator circuitry, memory, instructions, and processor circuitry. The network communicator circuitry is to send a first portion of a multi-part secret key to a first secret holder node, and send a plurality of shares of a second portion of the multi-part secret key to second secret holder nodes. The processor circuitry is to execute the instructions to combine responses from the first secret holder node and at least one of the second secret holder nodes to generate a combined authentication message, the network communicator circuitry to send the combined authentication message to a terminal node for authentication.


