Key Use Permission Management for Wireless Authentication Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems using key apparatuses with wireless communication face security risks due to distance-dependent vulnerabilities, where key apparatuses may respond unintentionally or leak unique ID information, especially in unencrypted communications over long ranges.

Innovation Solution

An information processing apparatus and method that includes a key storage unit for secret and public keys, and a key use permission state storage unit, allowing switching of key use permissions, enabling secure authentication without distance dependency through public key authentication schemes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless communication with key apparatus is enabled for distant authentication, then authentication convenience is improved, but security is worsened due to potential unintended responses and ID leakage

Engineering Contradiction:
Improveauthentication convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication system into multiple independent components: a key apparatus holding secret keys and a verification apparatus holding public keys. This segmentation allows the secret key to remain securely stored in the key apparatus while verification occurs separately in the verification apparatus, preventing unintended responses and ID leakage while maintaining authentication convenience.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces public keys as an intermediary element between the key apparatus and verification apparatus. Instead of directly transmitting or using secret keys for verification, the system uses public keys as a mediator that enables secure authentication without exposing the secret key, thus resolving the security risk in distant wireless communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If unencrypted wireless communication is used for key authentication, then communication simplicity is improved, but security is worsened due to potential information leakage

Engineering Contradiction:
Improvecommunication complexityVSAvoidinformation leakage
Core Design Contradiction:
Device complexityVSObject-generated harmful factors

Solution Approach 1:

The patent extracts the sensitive secret key information from the communication process entirely. The secret key remains exclusively stored in the key apparatus and is never transmitted. Only public keys and verification results are communicated, which contain no sensitive information that could be leaked, thus maintaining communication simplicity while eliminating information leakage risks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses public keys as disposable, non-sensitive information that can be freely transmitted without encryption. Public keys serve as a one-way communication element that provides authentication capability without the need for complex encryption mechanisms, simplifying communication while preventing information leakage.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS10447673B2Information processing apparatus, information processing method, and computer program
Publication Date: 2019.10.15 SONY GROUP CORP
  • US10447673B2 patent drawing
  • US10447673B2 patent drawing
  • US10447673B2 patent drawing

AI summary

To be capable of guaranteeing security without dependency on a distance of wireless communication while maintaining convenience of a key apparatus, there is provided an information processing apparatus including: a key storage unit configured to retain one or more secret keys corresponding to one or more respective public keys; and a key use permission state storage unit configured to store presence or absence of use permission of each of the one or more secret keys. For at least any of the one or more secret keys, a switch between the presence and absence of the use permission stored by the key use permission state storage unit is possible.