Mobile Device Access via Elliptic Curve Diffie-Hellman Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional methods for accessing system functionality, such as physical keys or electronic key fobs, are inconvenient and vulnerable to unauthorized access if lost or stolen, lacking secure and efficient alternatives for authentication.
Innovation Solution
A mobile device uses asymmetric cryptography to establish a secure channel with a system, employing a secure element to store and manage key pairs, enabling secure authentication and authorization through elliptic curve Diffie-Hellman key exchange and secure circuitry for tamper-resistant operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical keys or electronic key fobs are used for access, then system functionality can be accessed, but convenience deteriorates and security worsens when keys are lost or stolen
Solution Approach 1:
The patent replaces physical mechanical keys with a mobile device-based authentication system that uses cryptographic protocols (Diffie-Hellman key exchange, digital signatures) to establish secure access. This substitution eliminates the physical form factor that can be lost or stolen, while providing more convenient access through a digital device that can store multiple credentials and perform cryptographic operations.
Solution Approach 2:
The patent introduces a server as an intermediary that manages cryptographic key pairs and authentication credentials. The server acts as a trusted third party that issues digital credentials to mobile devices and verifies authentication requests, replacing the direct key-system interaction with a more secure mediated process that enhances both convenience and security.
2Ease of operation
If traditional electronic key fobs are used, then access is enabled, but vulnerability to unauthorized access increases if lost or stolen
Solution Approach 1:
The patent replaces electronic key fobs with a mobile device that performs cryptographic authentication. Instead of relying on a physical token that can be copied or cloned, the system uses asymmetric cryptography where the private key never leaves the secure element of the mobile device, making unauthorized duplication computationally infeasible while maintaining ease of access.
Solution Approach 2:
The patent implements preliminary authentication steps including Diffie-Hellman key exchange and digital signature verification before granting access. These preliminary cryptographic actions ensure that even if a mobile device is compromised, unauthorized access requires solving cryptographic problems that are computationally infeasible, thereby preventing harmful factors.
3Reliability
If cryptographic authentication is implemented, then security is improved, but system complexity increases
Solution Approach 1:
The patent uses a server as an intermediary to manage the complexity of cryptographic operations. The server handles key pair generation, certificate issuance, and authentication verification, allowing the mobile device and access system to use standardized cryptographic protocols without implementing complex key management infrastructure themselves, thus improving security while managing complexity.
Solution Approach 2:
The patent implements a universal authentication system where a single mobile device can authenticate to multiple different access systems using the same cryptographic credentials. This multi-functional approach allows the same cryptographic infrastructure to serve multiple purposes (door access, vehicle access, building access), reducing overall system complexity through standardization while maintaining high security.
Data Source
AI summary
Techniques are disclosed relating to electronic security, e.g., for authenticating a mobile electronic device to allow access to system functionality (e.g., physical access to the system, starting an engine/motor, etc.). In some embodiments, a system and mobile device exchange public keys of public key pairs during a pairing process. In some embodiments, an asymmetric transaction process includes generating a shared secret using a key derivation function over a key established using a secure key exchange (e.g., elliptic curve Diffie-Hellman), and verifying a signature of the system before transmitting any information identifying the mobile device. In various embodiments, disclosed techniques may increase transaction security and privacy of identifying information.


