Local Trust Manager for Decentralized Peer-to-Peer Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face complexities in accessing services across different networks due to requirements for registration, network affinity, identification, authorization, payment, and privacy management, especially when interacting with unknown or untrusted parties, and existing solutions rely on central authorities for trust verification.

Innovation Solution

A method utilizing a local trusted unit and a local trust manager that provides policy-related information to enable secure interactions between parties without the need for a third-party trust center, allowing for peer-to-peer authentication and trust management, with the local trust manager acting as a virtual trust provider to manage and verify trust levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a third-party trust center is used for verification, then trust assurance and integrity verification are improved, but device complexity and dependency on external authorities increase

Engineering Contradiction:
Improvetrust assuranceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service trust verification by enabling devices to autonomously generate and verify trust credentials locally without requiring external trust centers. The trust verification process is performed independently by the devices themselves, eliminating dependency on third-party authorities while maintaining reliability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts the trust verification function from external third-party trust centers and relocates it to local devices. By taking out the dependency on external authorities and embedding trust management capabilities directly in the devices, the system reduces complexity while maintaining trust assurance.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If multiple service access processes are implemented, then service security and authorization are improved, but ease of operation and user convenience deteriorate

Engineering Contradiction:
Improveservice securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a universal trust credential that can be used across multiple services and networks. Instead of requiring separate authentication processes for each service, the system uses a single trust credential that provides multi-functional access, maintaining security while significantly improving ease of operation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent performs trust verification and credential validation in advance, before the user needs to access services. By preliminarily establishing trust relationships and caching verification results, the system eliminates the need for repeated authentication processes, thereby improving user convenience without compromising security.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If peer-to-peer trust establishment is implemented, then ease of operation and speed are improved, but reliability and trust assurance may deteriorate without third-party verification

Engineering Contradiction:
Improveoperational simplicityVSAvoidtrust level
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs preliminary trust credential generation and verification before peer-to-peer interactions. By pre-establishing trust credentials and validating them in advance, the system ensures high reliability while maintaining the simplicity and speed of peer-to-peer operations during actual service access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual third-party verification processes with automated cryptographic verification mechanisms. The trust verification is performed automatically using mathematical proofs and digital signatures, eliminating the need for mechanical involvement of third parties while maintaining or even enhancing trust assurance.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3557456B1Method and device for data processing and communication system comprising such device
Publication Date: 2020.10.21 NOKIA SOLUTIONS & NETWORKS OY
  • EP3557456B1 patent drawingFigure 1
  • EP3557456B1 patent drawingFigure 2
  • EP3557456B1 patent drawingFigure 3~4

AI summary

A method and a device for data processing are provided comprising a first instance comprising at least one local trusted unit (LTU) and a local trust manager (LTM), the method comprising the step: The local trust manager provides a policy related information to the at least one local trusted unit and/or to a second instance.