Mutual Device Authentication Using Cross-Stage Secret Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods between electronic devices are vulnerable to impersonation attacks, particularly when a mutually trusted third party is compromised, and there is a need for enhanced security to prevent unauthorized access and ensure identity verification.

Innovation Solution

A method involving a remote electronic device and a first electronic device that uses a temporary private key to generate temporary public keys and a cross-stage secret key, combined with cryptographic authentication codes, to establish a common secret key and verify the possession of the cross-stage secret key, ensuring secure authentication without revealing unique authentication information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a pre-shared mutually trusted third party is used for authentication, then authentication can be established, but the system becomes vulnerable to impersonation attacks when the third party is compromised

Engineering Contradiction:
Improveauthentication securityVSAvoidimpersonation risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication dependency from the third party by enabling direct mutual authentication between devices. Each device generates its own authentication codes and verifies the other's codes directly, eliminating the need for a trusted third party and thus removing the impersonation risk associated with third party compromise.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces cryptographic authentication codes as intermediaries that enable direct verification between devices. These codes act as mediators that carry authentication information without requiring a trusted third party, allowing devices to verify each other's identities through code exchange and verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic authentication codes are transmitted offline, then leakage of authentication codes is mitigated, but the authentication process requires additional complexity

Engineering Contradiction:
Improvecode securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-generating and storing authentication codes in a secure element before the actual authentication process. These pre-stored codes are then used during authentication without requiring real-time generation or transmission, simplifying the online authentication process while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service by having each device use its own pre-stored authentication codes to verify the other device's codes independently. The authentication process becomes self-contained without requiring external intervention or complex coordination, reducing the operational complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20260046149A1Method of authentication between electronic devices
Publication Date: 2026.02.12 FU JIAN FA BA WANG INFORMATION TECH CO LTD
  • US20260046149A1 patent drawing
  • US20260046149A1 patent drawing
  • US20260046149A1 patent drawing

AI summary

This disclosure relates to a first electronic device, a remote electronic device, a method of authentication between electronic devices. The method is applicable in a mutual dynamic authentication, and the method includes: initiating, by a first electronic device, registration with a remote electronic device for registering an identity belonging to the first electronic device with the remote electronic device, by: calculating a second cryptographic authentication code; and securing first information and second information from being tampered with by a middleman; wherein the first information is sent by the first electronic device to the remote electronic device, and includes a first public key and a second public key of the first electronic device; and wherein the second information is received from the remote electronic device, and the second information includes a first public key and a second public key of the remote electronic device.