Mutual Authentication Circuit Using One-Round Hardware Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information processing systems with communication devices and semiconductor memories face inefficiencies and vulnerabilities in mutual authentication, leading to prolonged processing times and potential fraudulent data access due to software-based authentication and susceptibility to attacker manipulation.

Innovation Solution

Implementing a one-round communication method for mutual authentication between communication devices and storage devices using distinct number sequences for generating and verifying authentication codes, with hardware-based control circuits to enhance security and prevent fraudulent access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If general challenge-response mutual authentication is used with sequential communication rounds, then authentication security is maintained, but authentication time is prolonged and processing efficiency decreases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines the authentication processes of both devices into a single communication round. The host device sends a first authentication code that includes a first random number, and the storage device responds with a second authentication code that includes a second random number. Both devices verify each other's authenticity simultaneously through this single exchange, merging what would traditionally require separate communication rounds into one efficient interaction.

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If software-based mutual authentication is implemented using microprocessor processing, then authentication functionality is achieved, but susceptibility to attacker manipulation increases and security reliability decreases

Engineering Contradiction:
Improveauthentication functionalityVSAvoidsecurity reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent replaces software-based authentication processing with hardware-based authentication circuits. The host device includes an authentication circuit that generates and verifies authentication codes, while the storage device includes a corresponding authentication circuit that performs reciprocal verification. This hardware implementation eliminates the vulnerability to software attacks and manipulation that plagues microprocessor-based authentication systems.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If multiple authentication procedures are prepared in advance with CPU selection, then authentication flexibility is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent uses dynamic parameter changes through random number generation to provide authentication flexibility. The host device generates a first random number that is incorporated into the authentication code, and the storage device generates a second random number for its authentication code. These changing parameters ensure that each authentication session is unique and secure, eliminating the need for multiple pre-prepared authentication procedures while maintaining flexibility.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9959403B2Information processing system for mutual authentication between communication device and storage
Publication Date: 2018.05.01 MEGACHIPS
  • US9959403B2 patent drawing
  • US9959403B2 patent drawing
  • US9959403B2 patent drawing

AI summary

The communication device sends an authentication code (N) to a semiconductor memory to instruct the semiconductor memory to authenticate the communication device. The semiconductor memory authenticates the communication device based on the authentication code (N), and if the communication device is determined to be valid, sends an authentication code (N+1) to the communication device to instruct the communication device to authenticate the semiconductor memory in response to the authentication code (N). The communication device authenticates the semiconductor memory based on the authentication code (N+1).