Heterogeneous Network Authentication via Distributed Secret Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication protocols treat devices homogenously, ignoring their unique capabilities and features, leading to inefficient and inaccurate authentication processes by using a lowest common denominator approach.

Innovation Solution

A networked system with heterogeneous nodes, including a gateway node, secret holder nodes, and localizer nodes, that generate and combine responses based on specific capabilities, utilizing cryptographic functions and location information to create a more accurate and efficient authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If authentication protocols treat all devices homogenously, then the authentication process is simplified and easier to implement, but the authentication accuracy and efficiency deteriorate because device-specific capabilities are ignored

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidauthentication accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent applies local quality by enabling each device to contribute authentication data according to its specific capabilities. Instead of treating all devices uniformly, the system allows devices with location capabilities to provide location information, devices with sensor capabilities to provide sensor data, and so forth. This ensures that each device contributes what it is best at, improving overall authentication accuracy while maintaining protocol simplicity through the standardized challenge-response framework.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If multiple devices are combined to generate authentication responses, then authentication accuracy improves by leveraging diverse capabilities, but the system complexity increases due to coordination requirements

Engineering Contradiction:
Improveauthentication accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges multiple device responses into a single combined authentication credential. The server issues a challenge that is distributed to multiple devices, each of which generates a response based on its capabilities. These individual responses are then combined by the server to form a comprehensive authentication decision, leveraging the strengths of each device while maintaining a unified authentication process.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The server acts as an intermediary that coordinates the multi-device authentication process. It distributes challenges to appropriate devices based on the authentication context, collects responses from multiple devices, and combines these responses into a final authentication decision. This intermediary role simplifies the coordination complexity by centralizing the management of the authentication workflow.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If device-specific capabilities are utilized in authentication, then authentication efficiency improves by leveraging unique features, but the protocol complexity increases requiring different handling for different device types

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidprotocol complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies dynamics by making the authentication protocol adaptive to device capabilities. The server dynamically determines which devices to involve in the authentication process based on the authentication context and device capabilities. Devices respond to challenges based on their specific capabilities, and the server dynamically combines these responses. This dynamic approach allows the protocol to efficiently leverage device-specific features without requiring rigid, complex predefined handling for each device type.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11949780B2Technologies for multiple device authentication in a heterogeneous network
Publication Date: 2024.04.02 INTEL CORP
  • US11949780B2 patent drawing
  • US11949780B2 patent drawing
  • US11949780B2 patent drawing

AI summary

A disclosed example gateway node includes network communicator circuitry, memory, instructions, and processor circuitry. The network communicator circuitry is to send a first portion of a multi-part secret key to a first secret holder node, and send a plurality of shares of a second portion of the multi-part secret key to second secret holder nodes. The processor circuitry is to execute the instructions to combine responses from the first secret holder node and at least one of the second secret holder nodes to generate a combined authentication message, the network communicator circuitry to send the combined authentication message to a terminal node for authentication.