Mutual Identity Authentication With Public-Key Identity Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

During mutual identity authentication between a requester (REQ) and an authentication access controller (AAC) in a communication network, the interception of private and sensitive identity information by attackers poses a significant security risk, compromising the legitimacy of user and network access.

Innovation Solution

An identity authentication method involving an authentication server (AS) is employed, where identity information is encrypted using public keys, and authentication results are protected with nonces and digital signatures, ensuring confidentiality and legitimacy verification between the REQ and AAC.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If identity information is transmitted in plaintext during mutual authentication, then authentication can be completed, but security is compromised due to potential interception by attackers

Engineering Contradiction:
Improveauthentication securityVSAvoidencryption complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing encryption certificates and public-private key pairs for both the requester and authentication access controller before authentication occurs. This allows identity information to be encrypted in advance using public keys, so that when authentication happens, the encrypted data can be securely transmitted without real-time encryption complexity, thus maintaining security while reducing operational complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism through the use of authentication servers and certificate authorities that mediate the authentication process. These intermediaries verify digital certificates and manage key pairs, allowing the system to maintain security through standardized cryptographic protocols without requiring complex custom encryption implementations at each endpoint.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If digital certificates are used for identity authentication, then legitimacy verification is achieved, but sensitive information exposure risk increases during transmission

Engineering Contradiction:
Improveidentity verificationVSAvoidinformation interception
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive identity information from the transmission process by using digital certificates as standalone authentication credentials. Instead of transmitting raw identity data (names, IDs, addresses), the system uses extracted certificate-based identifiers that verify legitimacy without exposing personal information. The certificate contains only necessary verification data, separating identity proof from sensitive personal details.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses digital certificates as secure copies of identity credentials. Rather than transmitting actual identity information, the system transmits cryptographic copies (certificates) that prove identity without revealing the underlying sensitive data. These certificate copies can be verified by authentication servers to confirm legitimacy while maintaining the confidentiality of the original identity information.

Inventive Principle:
Principle #26Copying

3Reliability

If public key encryption is used to protect identity information, then confidentiality is maintained, but computational overhead increases

Engineering Contradiction:
Improvedata confidentialityVSAvoidcomputational energy
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the cryptographic operations into distinct phases: key pair generation, certificate creation, encryption using public keys, and decryption using private keys. This segmentation allows the system to use computationally intensive public key encryption only when necessary (during initial authentication and key exchange), while subsequent communications can use more efficient symmetric encryption methods, reducing overall computational energy consumption while maintaining confidentiality.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12375483B2Identity authentication method and apparatus, device, chip, storage medium, and program
Publication Date: 2025.07.29 CHINA IWNCOMM
  • US12375483B2 patent drawing
  • US12375483B2 patent drawing
  • US12375483B2 patent drawing

AI summary

An identity authentication method and apparatus, a device, a chip, a storage medium, and a program. Confidentiality processing is performed on identity information of a requesting device and an authentication access controller, such that the identity information of the requesting device and the authentication access controller is prevented from being exposed during a transmission process, thereby ensuring that an attacker cannot obtain private and sensitive information of the requesting device and the authentication access controller. In addition, by means of involving an authentication server, mutual identity authentication of the requesting device and the authentication access controller is realized while the confidentiality of information related to an entity identity is ensured.