Proxy Certification Unit for Cross-Organization Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods require device authentication to be performed independently, necessitating the saving of device keys and digital certificates on each device, which is time-consuming and labor-intensive when adding new devices.
Innovation Solution
An authentication system that includes a proxy certification unit to encrypt and send a hello message using a client private key, allowing user authentication across organizations without the need for device keys or digital certificates to be saved on the user terminal.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device authentication is performed independently using device keys and digital certificates saved on each device, then authentication security is improved, but device complexity and setup time increase
Solution Approach 1:
The patent introduces a certificate issuing device as an intermediary between the user terminal and the authentication system. This mediator generates and manages device certificates centrally, eliminating the need for each device to independently store and manage complex authentication credentials. The intermediary handles the cryptographic operations and certificate distribution, simplifying the user terminal while maintaining security through centralized control.
Solution Approach 2:
The patent creates a universal authentication mechanism where a single device certificate issued by the certificate issuing device can be used across multiple terminals and services. Instead of requiring separate device keys and certificates for each device, the system uses a unified certificate structure that works universally across the federation, reducing device complexity while maintaining security.
2Reliability
If device keys and digital certificates are saved on each device for authentication, then authentication reliability is improved, but time and labor for adding new devices increase
Solution Approach 1:
The certificate issuing device performs preliminary actions by pre-generating and storing device information in its internal storage before actual authentication is needed. When a new device is added, the system can quickly retrieve pre-prepared certificate templates and issue certificates without requiring time-consuming key generation and security configuration on the device itself, thus reducing setup time while maintaining reliability.
Solution Approach 2:
The certificate issuing device acts as an intermediary that centralizes the time-consuming operations of key management and certificate issuance. Instead of requiring manual configuration on each device, the intermediary automatically handles certificate generation and distribution, dramatically reducing the time and labor needed to add new devices while ensuring authentication reliability through centralized control.
3Adaptability or versatility
If multiple client certificates are issued for each terminal used by a user, then user authentication across multiple organizations is enabled, but device complexity and management overhead increase
Solution Approach 1:
The patent uses a template-based approach where a master device information template is created and then copied/ instantiated for multiple terminals. Instead of managing completely separate certificates for each device, the system uses template instantiation to generate device information for multiple terminals from a single source, enabling cross-organization authentication while simplifying management through template reuse.
Solution Approach 2:
The patent creates a universal device information structure that can serve multiple terminals and organizations simultaneously. The device information issued by the certificate issuing device is designed to be universally applicable across different terminals and organizational boundaries, eliminating the need for separate certificate management for each device while enabling broad adaptability for cross-organization authentication scenarios.
Data Source
AI summary
In an authentication system (120) of a first organization that a first user belongs to, when the first user accesses a service of another organization from a user terminal of the first organization, an authentication device (300) receives a hello message from another organization system, encrypts the hello message using a client private key of the first user, and sends the encrypted hello message to said another organization system as a signature message.


