Multi-role Authentication Chip with Encrypted Credential Decryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication processes for users with multiple roles are cumbersome and inefficient, requiring users to switch between chips for different roles.

Innovation Solution

A method where a device receives data from a chip, retrieves an encrypted credential, sends a decryption request to the chip, and verifies the credential's validity, allowing the device to authenticate the chip securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users switch between chips for different roles, then authentication for multiple roles is achieved, but the operation becomes cumbersome and tedious

Engineering Contradiction:
Improvemulti-role authentication capabilityVSAvoidauthentication operation complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent merges multiple role credentials into a single chip by storing multiple encrypted credentials (each associated with a different user role) within the same secure element. The authentication device retrieves the appropriate encrypted credential based on the chip identifier and decrypts it using the corresponding secret key stored in the chip, allowing one chip to handle multiple roles without requiring physical chip switching.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The chip is designed with multi-functionality to store and manage multiple encrypted credentials for different user roles simultaneously. The authentication system enables a single chip to serve multiple authentication purposes by selecting and decrypting the appropriate credential based on the requested role, making the chip universal across different user roles.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple chips are used for different roles, then role-specific authentication is secured, but device complexity increases

Engineering Contradiction:
Improverole-specific authentication securityVSAvoidchip management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple encrypted credentials for different roles are combined and stored within a single chip's secure memory. The authentication device manages this complexity by retrieving the chip identifier, selecting the corresponding encrypted credential, and coordinating the decryption process using the secret key stored in the chip, thereby maintaining security while reducing the number of physical chips needed.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If a single chip stores multiple encrypted credentials, then authentication efficiency is improved, but security management becomes more challenging

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidcredential management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The authentication device acts as an intermediary that manages the complexity of multiple encrypted credentials stored in the chip. It retrieves the chip identifier, selects the appropriate encrypted credential from its storage, and coordinates the decryption process by providing the secret key to the chip. This intermediary role simplifies credential management while maintaining high authentication efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3987419B1Method and chip for authenticating to a device and corresponding authentication device and system
Publication Date: 2025.04.23 THALES DIS CPL USA INC
  • EP3987419B1 patent drawingFigure 1~2

AI summary

The invention relates to a method (20) for authenticating to a device (12), comprising receiving (214), by the device, from a chip (14), data; retrieving (216), by the device, based on the received data, a predetermined encrypted credential; sending (218), by the device, to the chip, a decryption request for decrypting the encrypted credential including or being accompanied with the encrypted credential to be decrypted; retrieving (220), by the chip, a secret key; decrypting (222), by the chip, the encrypted credential by using the secret key; sending (224), by the chip, to the device, as a decryption request response, the credential; verifying (226), by the device, whether the credential is or is not valid; and authenticating (228), by the device, only if the credential is valid, the chip.