Mutual Authentication Protocol for Networked Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing protocols for authenticating networked devices primarily focus on client device authentication by a server device, lacking mechanisms for mutual authentication, dynamic credential generation, and role-based authentication, especially in non-web-based communication contexts.

Innovation Solution

The method involves a server device and client device exchanging authentication credentials, with the server dynamically generating credentials upon client request and both devices authenticating each other based on predefined criteria, incorporating role-based access to determine communication scope and privileges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing authentication protocols are used, then client device authentication by server device is achieved, but mutual authentication capability is lacking

Engineering Contradiction:
Improveauthentication securityVSAvoidmutual authentication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements bidirectional authentication where both client and server devices authenticate each other, inverting the traditional unidirectional model. The server device authenticates the client device using certificate verification, while simultaneously the client device authenticates the server device using received authentication credentials, achieving mutual authentication that enhances both security and adaptability

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The authentication system is designed to work across multiple communication contexts beyond web-based applications. The protocol framework enables universal application in various networked device communications, providing both client-to-server and server-to-client authentication capabilities within a single unified system

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If static authentication credentials are used, then initial authentication is achieved, but dynamic credential generation capability is lacking

Engineering Contradiction:
Improveauthentication validityVSAvoiddynamic credential generation
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system transitions from static authentication credentials to dynamic credential generation. The server device receives authentication requests from client devices and dynamically generates appropriate authentication credentials based on the specific communication context, device roles, and security requirements. This dynamic approach maintains authentication validity while adapting to different scenarios

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The server device prepares and transmits authentication credentials to the client device in advance before the actual communication begins. This preliminary action allows the client device to have the necessary credentials ready for mutual authentication, enabling flexible and context-appropriate authentication without requiring real-time credential creation during communication

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If basic authentication is implemented, then access control is achieved, but role-based access control capability is lacking

Engineering Contradiction:
Improveaccess controlVSAvoidrole-based access control
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The authentication system implements role-based access control by assigning different authentication credentials and access privileges to different device roles. Each device receives authentication credentials tailored to its specific role in the communication, enabling differentiated access control where clients and servers have distinct capabilities and permissions based on their functional requirements

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9172544B2Systems and methods for authentication between networked devices
Publication Date: 2015.10.27 GE DIGITAL HLDG LLC
  • US9172544B2 patent drawing
  • US9172544B2 patent drawing
  • US9172544B2 patent drawing

AI summary

Systems, methods, and computer-readable media are disclosed for authentication of networked devices in which a server device may authenticate a client device and/or a client device may authenticate a server device. Authentication credentials may be exchanged by the server device and the client device to enable mutual authentication. Upon authentication of the connection between the server device and the client device, authenticated, and potentially encrypted communications, may be exchanged by the server device and the client device.