Physical Port Authentication Using Shared Secrets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data protection techniques do not secure data from physical access attacks, allowing attackers to read and alter data by connecting directly to storage arrays or performing man-in-the-middle attacks.
Innovation Solution
A method involving the generation and validation of pseudo-random values and hash values based on shared secrets to authenticate communications between physical ports, establishing a secure encryption key for data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing data protection techniques are implemented, then data is protected from software attacks, but data is not protected from physical access attacks
Solution Approach 1:
The patent implements preliminary authentication actions before data transmission begins. Entities exchange pseudo-random values and validate hash values derived from shared secrets prior to establishing communication, preventing physical access attacks before they can compromise data
Solution Approach 2:
The patent introduces hash values and pseudo-random values as intermediary elements between communicating entities. These intermediaries enable verification of communication authenticity without exposing the underlying shared secret, adding a protective layer against physical access attacks
2Productivity
If physical access is granted to storage arrays or data connections, then data transmission can occur, but attackers can read and alter transmitted data
Solution Approach 1:
The patent implements feedback mechanisms where entities send pseudo-random values and receive validated hash values in return. This feedback loop confirms the authenticity of communication partners, preventing attackers from successfully reading or altering transmitted data even with physical access
Solution Approach 2:
The patent changes the parameter of communication security by introducing dynamic pseudo-random values and hash validation. Instead of static protection, the system uses changing parameters that prevent attackers from compromising data integrity through physical access
Data Source
AI summary
Techniques are provided for authenticating communications between physical ports using knowledge of shared secrets. One method comprises receiving, by a first entity, a connection request to establish a communication between physical ports of the first entity and a second entity; providing a first pseudo-random value to the second entity; obtaining a shared secret for communications with the second entity; generating a first hash value based on the shared secret and the first pseudo-random value; obtaining a second hash value from the second entity based on the shared secret and the first second pseudo-random value; and authenticating the communication in response to the first entity validating the first hash value using the second hash value. An encryption key based on the shared secret can protect communications between the physical ports of the first and second entities.


