Host System Authentication via Separate Communication Medium

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems face challenges in securely controlling access to physical communication connections, particularly in ensuring that only authorized devices can access sensitive information.

Innovation Solution

A method and system that utilize a separate authentication communication medium to authenticate connected modules before granting access to a secure communication medium, involving detection of connections, generation and verification of authentication challenges, and control of access through a multiplexer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a separate authentication communication medium is used to authenticate connected modules before granting access to the secure communication medium, then security against unauthorized access, cloning, and snooping is improved, but device complexity increases due to the need for multiple communication mediums and authentication protocols

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The communication system is segmented into two distinct communication mediums: an authentication communication medium for authentication purposes and a secure communication medium for data transmission. This segmentation allows the system to separate authentication functions from data transmission functions, thereby improving security while managing complexity through functional division.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication communication medium acts as an intermediary between the host system and the connected module during the authentication phase. This intermediary medium enables secure credential verification before establishing connections on the secure communication medium, preventing unauthorized access without requiring the secure medium to handle authentication protocols directly.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication challenges and responses are exchanged over a separate physical authentication connection, then protection against snooping on the secure communication medium is improved, but the system requires additional physical connections and interfaces increasing complexity

Engineering Contradiction:
Improveprotection against snoopingVSAvoidphysical connections
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The physical connection infrastructure is segmented into separate authentication and secure communication channels. The authentication communication medium carries authentication challenges and responses independently from the secure communication medium that carries encrypted data, preventing snooping on authentication credentials while maintaining manageable physical connectivity through dedicated channels.

Inventive Principle:
Principle #1Segmentation

3Reliability

If the host system generates and verifies authentication challenges using cryptographic protocols, then security against unauthorized access is improved, but processing time and computational resources increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication credentials including cryptographic keys are pre-configured in the connected module during manufacturing or initial setup. This preliminary configuration enables the module to rapidly respond to authentication challenges using pre-computed cryptographic operations, reducing authentication time while maintaining strong security through established cryptographic protocols.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12316786B2Secure medium intrusion prevention
Publication Date: 2025.05.27 SCHNEIDER ELECTRIC IT CORP
  • US12316786B2 patent drawing
  • US12316786B2 patent drawing
  • US12316786B2 patent drawing

AI summary

Examples of the disclosure include a host system comprising an authentication communication medium interface configured to be communicatively coupled to a connected module, a secure communication medium interface, and a controller configured to detect a connection of the connected module to the host system over a physical communication connection, generate an authentication challenge, provide the authentication challenge to the connected module over a physical authentication connection via the authentication communication medium interface, receive a challenge response to the authentication challenge from the connected module via the authentication communication medium interface, verify the challenge response, and grant the connected module access to host system data over the physical communication connection via the secure communication medium interface based on successful verification of the challenge response.