Proximity Authentication via Random Value Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for connecting devices to the internet often require cumbersome setup and increased security risks, particularly when devices lack built-in authentication capabilities, leading to inefficient user authentication processes and potential security vulnerabilities.

Innovation Solution

A system that uses proximity radio communication to transmit a random value between a user's device and equipment, with the server encoding and decoding this value to authenticate the user indirectly, thereby establishing a secure connection without constant connectivity and reducing the risk of malicious attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If connection processing is performed for all combinations between the terminal and the pieces of equipment in accordance with the FIDO specification, then authentication security is improved, but user operation complexity and time consumption increase significantly

Engineering Contradiction:
Improveauthentication securityVSAvoiduser operation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a server as an intermediary that manages authentication credentials for multiple devices. Instead of requiring the terminal to directly pair with each device individually, the server acts as a central coordinator that handles the authentication protocol, storing and managing the credentials that enable the terminal to authenticate with multiple devices through simplified operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary authentication and credential distribution through proximity radio communication before actual device usage. The terminal and devices establish secure credentials in advance when in close proximity, so that subsequent authentications can occur without repeated complex pairing processes, reducing operational complexity while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If the information processing device maintains constant connection standby state for authentication, then authentication availability is improved, but security vulnerability to malicious attacks increases

Engineering Contradiction:
Improveauthentication availabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements authentication on-demand rather than maintaining constant connection standby. The terminal initiates authentication only when needed for specific operations, and the system uses time-limited credentials that expire after use. This periodic, event-driven approach maintains authentication availability when required while minimizing exposure to security threats by not maintaining persistent vulnerable connections.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent uses disposable, single-use authentication credentials that are generated for specific authentication events and then invalidated. These short-lived credentials replace persistent authentication tokens, allowing the system to provide authentication availability on-demand while reducing security vulnerabilities by eliminating long-standing connection states that could be targeted by attackers.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If traditional authentication methods requiring password input or pattern input are used, then authentication security is maintained, but user convenience and operation speed decrease

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces manual authentication methods (password input, pattern drawing) with automatic proximity-based authentication. When the terminal detects a device through proximity radio communication, the authentication process is automatically initiated and completed through cryptographic verification of pre-established credentials, eliminating the need for manual user input while maintaining or enhancing security through cryptographic methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The authentication system performs self-service by automatically initiating and completing the authentication process without requiring user intervention for data entry. The terminal and devices automatically exchange and verify credentials through proximity communication, with the system managing the entire authentication sequence autonomously, thus reducing authentication time while maintaining security through automated cryptographic verification.

Inventive Principle:
Principle #25Self-service

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach simplifies user authentication across multiple devices by eliminating the need for constant connection and reduces security risks by ensuring that only authorized devices can authenticate, thus enhancing both convenience and security.

Implementation Method 1

transmitting a first random value by proximity radio communication to a device

Methodology Applied
Scientific EffectProximity radio communication: Electromagnetic Propulsion

Data Source

PatentEP3312750B1Information processing device, information processing system, and information processing method
Publication Date: 2020.01.08 FUJITSU LTD
  • EP3312750B1 patent drawingFigure 1~2
  • EP3312750B1 patent drawingFigure 3
  • EP3312750B1 patent drawingFigure 4

AI summary

A non-transitory, computer-readable recording medium having stored therein a program for causing a computer execute a process of transmitting a first random value by proximity radio communication to a device coupled via a server and a network, receiving data in which the first random value is encoded, from the device by the proximity radio communication, determining whether the first random value matches a value obtained by decoding the data with a server key obtained in advance from the server, when the value obtained by decoding the data matches the first random value, authenticating a user, and causing the information processing device to execute processing for transmitting a result of the authenticating the user to the server via the device.