Offline Device Authentication Using Distributed Security Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems for authenticating and authorizing devices in equipment control, such as vehicles or access systems, fail to function when there is no network connectivity, as they rely on communication with a centralized cloud and lack the ability to authenticate or authorize devices independently.

Innovation Solution

A distributed security model that enables authentication and authorization without internet connectivity by using a secure communications channel, end-to-end encryption, and a key attribute authorization model, allowing devices to authenticate and authorize actions locally using a portable device as a key, even offline.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional systems use centralized cloud authentication, then security can be managed centrally, but the system cannot authenticate devices when network connectivity is unavailable

Engineering Contradiction:
Improveauthentication capabilityVSAvoidoperational capability in disconnected environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authentication system is segmented into distributed components: each device stores its own authentication credentials and can independently verify other devices. This eliminates the single-point dependency on centralized cloud authentication, allowing devices to authenticate each other directly even when disconnected from the network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Authentication credentials and encryption keys are pre-configured in devices during manufacturing or initial setup. This preliminary action enables devices to perform authentication and authorization operations independently without requiring real-time connection to a centralized system, thus solving the offline operation problem.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If devices store authentication credentials locally, then offline authentication is possible, but security risk increases if device storage is compromised

Engineering Contradiction:
Improveoffline authentication capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

A secure element or hardware security module acts as an intermediary between the authentication credentials and the device's processing units. This intermediary provides a protected environment for storing and managing cryptographic keys, preventing direct access even if the device's software is compromised, thus mitigating security risks while enabling offline authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces software-based authentication storage with hardware-based secure elements that provide cryptographic protection. This substitution uses physical security mechanisms (secure enclaves, trusted platform modules) to protect credentials, making extraction significantly more difficult compared to traditional software storage methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If a distributed authentication model is implemented, then offline operation is enabled, but system complexity increases

Engineering Contradiction:
Improvedisconnected operation capabilityVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication protocol that can operate in multiple modes: online mode where devices can sync with centralized systems, and offline mode where devices authenticate independently. The same core authentication mechanism handles both scenarios, reducing the need for separate complex systems for each mode and thereby managing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11895247B2System and method for authenticating and authorizing devices
Publication Date: 2024.02.06 DENSO CORP
  • US11895247B2 patent drawing
  • US11895247B2 patent drawing
  • US11895247B2 patent drawing

AI summary

A system and method for a distributed security model that may be used to achieve one or more of the following: authenticate system components; securely transport messages between system components; establish a secure communications channel over a constrained link; authenticate message content; authorize actions; and distribute authorizations and configuration data amongst users' system components in a device-as-a-key system.