Mutual Identity Authentication With Public-Key Identity Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
During mutual identity authentication between a requester (REQ) and an authentication access controller (AAC) in a communication network, the interception of private and sensitive identity information by attackers poses a significant security risk, compromising the legitimacy of user and network access.
Innovation Solution
An identity authentication method involving an authentication server (AS) is employed, where identity information is encrypted using public keys, and authentication results are protected with nonces and digital signatures, ensuring confidentiality and legitimacy verification between the REQ and AAC.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If identity information is transmitted in plaintext during mutual authentication, then authentication can be completed, but security is compromised due to potential interception by attackers
Solution Approach 1:
The patent applies preliminary action by pre-establishing encryption certificates and public-private key pairs for both the requester and authentication access controller before authentication occurs. This allows identity information to be encrypted in advance using public keys, so that when authentication happens, the encrypted data can be securely transmitted without real-time encryption complexity, thus maintaining security while reducing operational complexity.
Solution Approach 2:
The patent introduces an intermediary mechanism through the use of authentication servers and certificate authorities that mediate the authentication process. These intermediaries verify digital certificates and manage key pairs, allowing the system to maintain security through standardized cryptographic protocols without requiring complex custom encryption implementations at each endpoint.
2Reliability
If digital certificates are used for identity authentication, then legitimacy verification is achieved, but sensitive information exposure risk increases during transmission
Solution Approach 1:
The patent extracts the sensitive identity information from the transmission process by using digital certificates as standalone authentication credentials. Instead of transmitting raw identity data (names, IDs, addresses), the system uses extracted certificate-based identifiers that verify legitimacy without exposing personal information. The certificate contains only necessary verification data, separating identity proof from sensitive personal details.
Solution Approach 2:
The patent uses digital certificates as secure copies of identity credentials. Rather than transmitting actual identity information, the system transmits cryptographic copies (certificates) that prove identity without revealing the underlying sensitive data. These certificate copies can be verified by authentication servers to confirm legitimacy while maintaining the confidentiality of the original identity information.
3Reliability
If public key encryption is used to protect identity information, then confidentiality is maintained, but computational overhead increases
Solution Approach 1:
The patent segments the cryptographic operations into distinct phases: key pair generation, certificate creation, encryption using public keys, and decryption using private keys. This segmentation allows the system to use computationally intensive public key encryption only when necessary (during initial authentication and key exchange), while subsequent communications can use more efficient symmetric encryption methods, reducing overall computational energy consumption while maintaining confidentiality.
Data Source
AI summary
An identity authentication method and apparatus, a device, a chip, a storage medium, and a program. Confidentiality processing is performed on identity information of a requesting device and an authentication access controller, such that the identity information of the requesting device and the authentication access controller is prevented from being exposed during a transmission process, thereby ensuring that an attacker cannot obtain private and sensitive information of the requesting device and the authentication access controller. In addition, by means of involving an authentication server, mutual identity authentication of the requesting device and the authentication access controller is realized while the confidentiality of information related to an entity identity is ensured.


