P2P Authentication Certificate Chain for Secure Device Handover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing peer-to-peer (P2P) services between electronic devices using short-range communication schemes face challenges such as redundant service characteristics and vulnerability to man-in-the-middle (MITM) attacks, requiring users to identify the communication scheme in advance and exposing personal information during authentication.

Innovation Solution

An electronic device capable of performing P2P services through multiple communication schemes, utilizing a public key for verification and a shared key for authentication to prevent MITM attacks, with a method that includes receiving a public key, generating an authentication certificate chain, and decrypting encrypted information to ensure secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If P2P services use short-range communication schemes, then communication speed and efficiency are improved, but vulnerability to MITM attacks increases

Engineering Contradiction:
Improvecommunication speedVSAvoidsecurity against MITM attacks
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent performs authentication and certificate verification before establishing the P2P communication channel. The electronic device receives and verifies authentication certificate chains from external devices prior to service execution, preventing MITM attacks by ensuring device identity is confirmed in advance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces authentication certificate chains as an intermediary verification mechanism between communicating devices. These certificate chains act as a trusted mediator that validates device identities, allowing secure communication without exposing personal information while preventing unauthorized interception.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If P2P services require users to identify communication schemes in advance, then service compatibility is improved, but user operation complexity increases

Engineering Contradiction:
Improveservice compatibilityVSAvoiduser operation simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent enables the electronic device to automatically detect, identify, and select appropriate communication schemes without user intervention. The device autonomously determines the communication protocol based on the external device's capabilities and service requirements, eliminating the need for users to manually identify or configure communication schemes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements a universal authentication mechanism that works across multiple communication schemes. The authentication certificate chain verification process is scheme-agnostic, allowing the same authentication framework to support Bluetooth, Wi-Fi Direct, and other short-range communication protocols, thereby improving service compatibility without requiring scheme-specific authentication procedures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If P2P services transmit personal information during authentication, then authentication accuracy is improved, but information security deteriorates

Engineering Contradiction:
Improveauthentication accuracyVSAvoidpersonal information exposure
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The patent extracts and removes personal information from the authentication process. Instead of transmitting telephone numbers or other personally identifiable information, the system uses authentication certificate chains that contain device identity verification data without exposing user personal information. The certificate chains are verified cryptographically to ensure authentication accuracy without requiring personal data transmission.

Inventive Principle:
Principle #2Taking out (Extraction)

4Adaptability or versatility

If multiple communication schemes are supported, then service versatility is improved, but device complexity increases

Engineering Contradiction:
Improvecommunication scheme supportVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication mechanisms of multiple communication schemes into a single unified framework. By implementing a common authentication interface that works across Bluetooth, Wi-Fi Direct, and other protocols, the system reduces complexity compared to maintaining separate authentication systems for each communication scheme. The authentication certificate chain verification process serves as a universal layer that simplifies multi-scheme support.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP4102770B1Electronic device and method for performing peer to peer service in electronic device
Publication Date: 2025.04.02 SAMSUNG ELECTRONICS CO LTD
  • EP4102770B1 patent drawingFigure 1
  • EP4102770B1 patent drawingFigure 2
  • EP4102770B1 patent drawingFigure 3

AI summary

Disclosed are an electronic device and a method for performing a P2P service in the electronic device, according to various embodiments of the present document, the electronic device comprising: a communication module; a processor; a memory; and a security module, wherein the memory may be configured to store instructions that, when executed, enable the processor to receive a public key from an external electronic device as a peer to pear (P2P) service is requested, transmit, to the external electronic device, an authentication certificate chain generated on the basis of the received public key via the security module, verify an authentication certificate chain received from the external electronic device by using a root authentication certificate stored in the security module, receive encrypted information of the external electronic device from the external electronic device, decrypt the encrypted information of the external electronic device by using a shared key generated according to a result of the verifying of the received authentication certificate chain, and perform the P2P service with the external electronic device via the communication module, on the basis of the decoded information of the external electronic device. Other various embodiments are possible.