Proximity Communication Trust via Shared Secret

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing proximity-based communication systems, such as those using NFC technology, require user acknowledgment or confirmation for secure interactions, which can render devices vulnerable to attacks and disrupt seamless device interactions, especially when users want to share content or execute actions across multiple devices without interruptions.

Innovation Solution

Establishing a trust mechanism between devices using a shared secret value that allows for secure, automatic verification of message integrity without relying on third-party certification or Public Key Infrastructure (PKI), enabling seamless communication and action execution across devices without user intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user acknowledgment or confirmation is required for secure interactions, then device security is improved, but user experience and communication seamlessness deteriorate

Engineering Contradiction:
Improvedevice securityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by establishing a shared secret between devices before actual communication occurs. This pre-established trust mechanism allows devices to automatically verify message integrity without requiring user acknowledgment during interactions, thus maintaining security while enabling seamless communication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The trust verification mechanism operates autonomously through self-service. Devices automatically verify message integrity using the pre-established shared secret without requiring user intervention. The system serves itself by independently confirming authentication and integrity, eliminating the need for user acknowledgment while maintaining security.

Inventive Principle:
Principle #25Self-service

2Reliability

If user acknowledgment is required for each interaction, then attack vulnerability is reduced, but communication efficiency and productivity deteriorate

Engineering Contradiction:
Improveattack resistanceVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Security measures are performed in advance by establishing a shared secret between devices before communication begins. This preliminary trust establishment enables automatic message integrity verification during interactions, maintaining attack resistance while eliminating the need for repeated user acknowledgments that would reduce communication efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The trust verification mechanism operates continuously and automatically throughout communication sessions. Devices maintain secure interactions through continuous automatic verification using the shared secret, eliminating interruptions caused by required user acknowledgments and thereby sustaining high communication efficiency while preserving security.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If third-party certification or PKI is used for verification, then authentication reliability is improved, but system complexity and device requirements worsen

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts and removes the dependency on third-party certification authorities and complex PKI infrastructure. Instead, it uses a simplified approach where devices directly share secrets with each other, maintaining authentication reliability while significantly reducing system complexity and eliminating the need for external certification services.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The shared secret acts as an intermediary trust mechanism between devices, replacing the need for third-party certification authorities. This direct peer-to-peer trust establishment maintains authentication reliability while simplifying the system architecture by removing complex PKI dependencies and intermediary certification services.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2732651B1Data integrity for proximity-based communication
Publication Date: 2018.09.05 BLACKBERRY LTD
  • EP2732651B1 patent drawingFigure 1A
  • EP2732651B1 patent drawingFigure 1B
  • EP2732651B1 patent drawingFigure 2

AI summary

Methods, systems, and computer programs for trusted communication among mobile devices are described. In some aspects, an authentication value is generated at a first mobile device based on a message and a shared secret value stored on the first mobile device. In response to detecting proximity of a second mobile device, the message and the authentication value are wirelessly transmitted from the first mobile device to the second mobile device. In some implementations, the message and the authentication value can be wirelessly transmitted by a proximity-activated wireless interface, such as, for example, a Near Field Communication (NFC) interface.