Management Server for Secure User-Mobile Body Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in securely tracking the use relationship between a user and a mobile body, such as a vehicle, especially in scenarios where the use is not based on a contract or reservation, leading to inefficiencies in payment processing and security concerns.

Innovation Solution

A management server that authenticates both the user and the mobile body through separate servers, using unique identifiers and information exchanged between user and mobile body terminals, to establish a secure correspondence and track the use relationship.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single server is used to authenticate both the user and the mobile body, then the authentication process is simpler, but security is compromised

Engineering Contradiction:
Improveauthentication process complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the authentication system into two separate servers: a first server for authenticating the user and a second server for authenticating the mobile body. This segmentation allows each server to specialize in authenticating a specific target, thereby enhancing overall security while maintaining manageable complexity in the authentication process.

Inventive Principle:
Principle #1Segmentation

2Productivity

If correspondence is established without authentication, then the use relationship tracking is faster, but security is compromised

Engineering Contradiction:
Improveuse relationship tracking speedVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent performs preliminary authentication of both the user and the mobile body through separate servers before establishing the correspondence relationship. This preliminary action ensures that security verification is completed in advance, allowing the use relationship tracking to proceed efficiently without compromising security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple servers are used for authentication, then security is enhanced, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication functions into separate, dedicated servers - one for user authentication and another for mobile body authentication. This extraction reduces the complexity within each individual server while maintaining enhanced security through the distributed architecture, as each server focuses on a specific authentication task.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If correspondence is terminated frequently, then security is maintained, but system stability decreases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent implements a mechanism where the management server receives termination requests from either the user terminal or mobile body terminal, and automatically terminates the correspondence relationship. This feedback mechanism allows the system to maintain security by responding to termination requests while providing stability through automated, consistent handling of correspondence lifecycle management.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250106204A1Management server, management method, and storage medium
Publication Date: 2025.03.27 TOYOTA JIDOSHA KK
  • US20250106204A1 patent drawing
  • US20250106204A1 patent drawing
  • US20250106204A1 patent drawing

AI summary

A management server according to one aspect of the present disclosure includes at least one processor. The processor receives a first identifier, first unique information, a second identifier, and second unique information in response to occurrence of a use relationship between a first target and a second target, requests authentication of the first target by transmitting the received first identifier and the received first unique information to a first server, requests authentication of the second target by transmitting the received second identifier and the received second unique information to a second server, and sets a correspondence between the first identifier and the second identifier when both the first target and the second target have successfully been authenticated.