OPACITY Protocol Authentication Key Establishment Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure communication technologies face challenges in balancing performance and security, particularly in contactless transactions where low computing power devices struggle with key establishment and incur high latency due to multiple request-response pairs, and there is a need for anonymous authentication without revealing user/device identification to non-participants.

Innovation Solution

The OPACITY system provides a protocol for secure authentication and key agreement that uses a single command for robust transactions, offering forward secrecy and privacy protection by generating an anonymous identifier and encrypted information, allowing devices to authenticate without revealing readable identification, and supports key revocation and anti-theft mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional key establishment protocols are used in contactless transactions, then security protection level is improved, but transaction latency and user wait time increase

Engineering Contradiction:
Improvesecurity protection levelVSAvoidtransaction latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-establishing cryptographic bindings between access control entities before transactions occur. The system pre-generates and stores binding information including public keys, certificates, and cryptographic parameters in a lookup table, so that during actual transactions, the system can quickly retrieve and use pre-computed security parameters instead of performing complex key establishment in real-time, thus reducing transaction latency while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the key establishment process into offline preparation phase and online transaction phase. The computationally intensive tasks of key pair generation, certificate creation, and binding computation are performed offline and stored. During online transactions, only lightweight verification and lookup operations are needed, separating heavy computation from time-critical operations to reduce latency

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple request-response pairs are used for authentication, then security is improved, but overhead and latency increase

Engineering Contradiction:
Improveauthentication securityVSAvoidnumber of requests and responses
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses preliminary action by pre-computing and storing authentication credentials and binding information before transactions. The system prepares authentication data including public keys, certificates, and binding parameters in advance, allowing single-request authentication during transactions without requiring multiple back-and-forth exchanges, thus reducing protocol overhead while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies copying by creating and storing duplicate copies of authentication credentials and binding information in lookup tables. Instead of requiring multiple verification exchanges, the system copies pre-validated authentication data to a readily accessible format, enabling single-request authentication where the responder can immediately verify credentials without iterative challenge-response sequences

Inventive Principle:
Principle #26Copying

3Ease of operation

If readable identification information is transmitted, then authentication is simplified, but privacy and identity protection are compromised

Engineering Contradiction:
Improveauthentication simplicityVSAvoidprivacy protection
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent applies asymmetry by using asymmetric cryptography where public keys and certificates are transmitted instead of readable identification information. The binding information includes cryptographic parameters that authenticate identity without exposing personal identifiers. This asymmetric approach allows authentication to proceed with cryptographic verification while keeping actual identity information private and protected

Inventive Principle:
Principle #4Asymmetry

Solution Approach 2:

The patent uses cryptographic certificates and binding information as intermediaries between identity verification and privacy protection. Instead of transmitting readable identification information directly, the system uses cryptographic intermediaries (certificates, public keys, binding data) that verify authenticity without revealing personal identity, thus protecting privacy while maintaining authentication functionality

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20120144193A1Open protocol for authentication and key establishment with privacy
Publication Date: 2012.06.07 ASSA ABLOY AB
  • US20120144193A1 patent drawing
  • US20120144193A1 patent drawing
  • US20120144193A1 patent drawing

AI summary

A suite of efficient authentication and key establishment protocols for securing contact or contactless interfaces between communicating systems. The protocols may be used in secure physical access, logical access and/or transportation applications, among other implementations. The system authenticates a mobile device such as a smart card and/or mobile phone equipped with a secure element presented to one or more host terminals and establishes shared secure messaging keys to protect communications between the device and terminal. Secure messaging provides an end-to-end protected path of digital documents or transactions through the interface. The protocols provide that the device does not reveal identification information to entities different from a trusted host. The terminal may be a contactless reader at a door for controlling physical access, a desktop, laptop or kiosk for controlling logical access, and/or an access point for obtaining an encrypted digital ticket from an authenticated mobile device used for transit applications.