Mutual Identity Authentication Through Encrypted Server Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity authentication methods in communication networks expose sensitive information during mutual identity authentication, leading to security risks due to interception by attackers.

Innovation Solution

An identity authentication method involving an authentication server that encrypts and decrypts identity information using message encryption keys and public keys, ensuring confidentiality and real-time authentication between a requester and an authentication access controller.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If identity information is transmitted during mutual identity authentication, then authentication can be performed, but sensitive information is exposed to attackers

Engineering Contradiction:
Improveauthentication securityVSAvoidinformation exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an authentication server as an intermediary that facilitates mutual identity authentication between the requester and AAC without requiring direct transmission of sensitive identity information between them. The authentication server acts as a mediator that verifies credentials and establishes authentication results, thereby preventing direct exposure of sensitive information during the authentication process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses digital certificates and public key infrastructure to create verified copies of identity information. Instead of transmitting raw sensitive data, the system transmits encrypted representations and digital signatures that can be verified without exposing the original sensitive information. The authentication server creates and verifies cryptographic copies of identity data, ensuring authentication while maintaining confidentiality.

Inventive Principle:
Principle #26Copying

2Object-affected harmful factors

If identity information is encrypted during transmission, then confidentiality is improved, but authentication complexity increases

Engineering Contradiction:
Improveinformation confidentialityVSAvoidauthentication process complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The authentication server handles the complex cryptographic operations as an intermediary, shielding the requester and AAC from the complexity of key management and encryption processes. The server performs encryption, decryption, and verification operations, simplifying the overall authentication process for the end users while maintaining strong security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system establishes cryptographic key pairs and certification relationships in advance before the actual authentication process. Digital certificates are pre-issued and distributed, allowing the authentication server to perform rapid verification without complex real-time cryptographic computations. This preliminary preparation reduces the complexity of the actual authentication transaction.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12362924B2Identity authentication method and apparatus, device, chip, storage medium, and program
Publication Date: 2025.07.15 CHINA IWNCOMM
  • US12362924B2 patent drawing
  • US12362924B2 patent drawing
  • US12362924B2 patent drawing

AI summary

Disclosed in embodiments of the present application are an identity authentication method and apparatus, a device, a chip, a storage medium, and a program. Identify information of a requesting device and an authentication access controller is subjected to confidential processing to prevent the identify information of the requesting device and the authentication access controller from being exposed in a transmission process, so as to ensure that an attacker cannot obtain the private and sensitive information. Moreover, an authentication server is introduced, such that real-time authentication of bidirectional identity between the requesting device and the authentication access controller is achieved while the confidentiality of entity identity related information is guaranteed.