P2P Authentication Certificate Chain for Secure Device Handover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing peer-to-peer (P2P) services between electronic devices using short-range communication schemes face challenges such as redundant service characteristics and vulnerability to man-in-the-middle (MITM) attacks, requiring users to identify the communication scheme in advance and exposing personal information during authentication.
Innovation Solution
An electronic device capable of performing P2P services through multiple communication schemes, utilizing a public key for verification and a shared key for authentication to prevent MITM attacks, with a method that includes receiving a public key, generating an authentication certificate chain, and decrypting encrypted information to ensure secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If P2P services use short-range communication schemes, then communication speed and efficiency are improved, but vulnerability to MITM attacks increases
Solution Approach 1:
The patent performs authentication and certificate verification before establishing the P2P communication channel. The electronic device receives and verifies authentication certificate chains from external devices prior to service execution, preventing MITM attacks by ensuring device identity is confirmed in advance.
Solution Approach 2:
The patent introduces authentication certificate chains as an intermediary verification mechanism between communicating devices. These certificate chains act as a trusted mediator that validates device identities, allowing secure communication without exposing personal information while preventing unauthorized interception.
2Adaptability or versatility
If P2P services require users to identify communication schemes in advance, then service compatibility is improved, but user operation complexity increases
Solution Approach 1:
The patent enables the electronic device to automatically detect, identify, and select appropriate communication schemes without user intervention. The device autonomously determines the communication protocol based on the external device's capabilities and service requirements, eliminating the need for users to manually identify or configure communication schemes.
Solution Approach 2:
The patent implements a universal authentication mechanism that works across multiple communication schemes. The authentication certificate chain verification process is scheme-agnostic, allowing the same authentication framework to support Bluetooth, Wi-Fi Direct, and other short-range communication protocols, thereby improving service compatibility without requiring scheme-specific authentication procedures.
3Measurement precision
If P2P services transmit personal information during authentication, then authentication accuracy is improved, but information security deteriorates
Solution Approach 1:
The patent extracts and removes personal information from the authentication process. Instead of transmitting telephone numbers or other personally identifiable information, the system uses authentication certificate chains that contain device identity verification data without exposing user personal information. The certificate chains are verified cryptographically to ensure authentication accuracy without requiring personal data transmission.
4Adaptability or versatility
If multiple communication schemes are supported, then service versatility is improved, but device complexity increases
Solution Approach 1:
The patent merges the authentication mechanisms of multiple communication schemes into a single unified framework. By implementing a common authentication interface that works across Bluetooth, Wi-Fi Direct, and other protocols, the system reduces complexity compared to maintaining separate authentication systems for each communication scheme. The authentication certificate chain verification process serves as a universal layer that simplifies multi-scheme support.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Disclosed are an electronic device and a method for performing a P2P service in the electronic device, according to various embodiments of the present document, the electronic device comprising: a communication module; a processor; a memory; and a security module, wherein the memory may be configured to store instructions that, when executed, enable the processor to receive a public key from an external electronic device as a peer to pear (P2P) service is requested, transmit, to the external electronic device, an authentication certificate chain generated on the basis of the received public key via the security module, verify an authentication certificate chain received from the external electronic device by using a root authentication certificate stored in the security module, receive encrypted information of the external electronic device from the external electronic device, decrypt the encrypted information of the external electronic device by using a shared key generated according to a result of the verifying of the received authentication certificate chain, and perform the P2P service with the external electronic device via the communication module, on the basis of the decoded information of the external electronic device. Other various embodiments are possible.