Proximity Communication Security via Shared Secret Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing proximity-based communication systems, such as those using NFC technology, require user acknowledgment or confirmation for secure interactions, which can render devices vulnerable to attacks and disrupt seamless device interactions, especially when users want to share content or execute actions across multiple devices without interruptions.

Innovation Solution

A method for establishing a shared secret between devices to verify the integrity of messages without user acknowledgment, using proximity-based wireless communication, allowing devices to trust each other and communicate securely without conventional Public Key Infrastructure (PKI) paradigms, enabling seamless data exchange and action execution across devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user acknowledgment or confirmation is required for secure interactions, then security is improved, but user experience deteriorates due to repeated pairing or confirmation steps

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by establishing a shared secret between devices before actual communication occurs. This pre-established secret enables automatic verification of messages without requiring user acknowledgment during subsequent interactions, thus maintaining security while improving user experience by eliminating repeated confirmation steps

Inventive Principle:
Principle #10Preliminary action

2Reliability

If conventional Public Key Infrastructure (PKI) paradigms are used, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts and removes the complex PKI infrastructure from the communication process. Instead of using certificates, public key pairs, and trusted certificate authorities, the invention uses a simplified approach where devices directly establish shared secrets and verify messages using this secret, thereby maintaining security while significantly reducing device complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The shared secret acts as an intermediary that enables secure communication without requiring the complex PKI infrastructure. This mediator allows devices to verify each other's authenticity and message integrity through a simple secret-based mechanism rather than through complex certificate validation processes

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2732652B1Data integrity for proximity-based communication
Publication Date: 2018.09.05 BLACKBERRY LTD
  • EP2732652B1 patent drawingFigure 1A
  • EP2732652B1 patent drawingFigure 1B
  • EP2732652B1 patent drawingFigure 2

AI summary

Methods, systems, and computer programs for trusted communication among mobile devices are described. In some aspects, information is wirelessly transmitted from a first mobile device to a second mobile device. The information permits the second mobile device to detect proximity of the first mobile device. In some implementations, the information can be wirelessly transmitted by a proximity- activated wireless interface, such as, for example, a Near Field Communication (NFC) interface. In response to the information, the first mobile device receives a message and a first authentication value wirelessly transmitted from the second mobile device to the first mobile device. A second authentication value is generated at the first mobile device based on the message and the shared secret value. Integrity of the message is verified based on comparing the first authentication value and the second authentication value.