Proxy Certification Unit for Cross-Organization Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods require device authentication to be performed independently, necessitating the saving of device keys and digital certificates on each device, which is time-consuming and labor-intensive when adding new devices.

Innovation Solution

An authentication system that includes a proxy certification unit to encrypt and send a hello message using a client private key, allowing user authentication across organizations without the need for device keys or digital certificates to be saved on the user terminal.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device authentication is performed independently using device keys and digital certificates saved on each device, then authentication security is improved, but device complexity and setup time increase

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a certificate issuing device as an intermediary between the user terminal and the authentication system. This mediator generates and manages device certificates centrally, eliminating the need for each device to independently store and manage complex authentication credentials. The intermediary handles the cryptographic operations and certificate distribution, simplifying the user terminal while maintaining security through centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal authentication mechanism where a single device certificate issued by the certificate issuing device can be used across multiple terminals and services. Instead of requiring separate device keys and certificates for each device, the system uses a unified certificate structure that works universally across the federation, reducing device complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If device keys and digital certificates are saved on each device for authentication, then authentication reliability is improved, but time and labor for adding new devices increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsetup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The certificate issuing device performs preliminary actions by pre-generating and storing device information in its internal storage before actual authentication is needed. When a new device is added, the system can quickly retrieve pre-prepared certificate templates and issue certificates without requiring time-consuming key generation and security configuration on the device itself, thus reducing setup time while maintaining reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The certificate issuing device acts as an intermediary that centralizes the time-consuming operations of key management and certificate issuance. Instead of requiring manual configuration on each device, the intermediary automatically handles certificate generation and distribution, dramatically reducing the time and labor needed to add new devices while ensuring authentication reliability through centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple client certificates are issued for each terminal used by a user, then user authentication across multiple organizations is enabled, but device complexity and management overhead increase

Engineering Contradiction:
Improvecross-organization authenticationVSAvoidcertificate management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent uses a template-based approach where a master device information template is created and then copied/ instantiated for multiple terminals. Instead of managing completely separate certificates for each device, the system uses template instantiation to generate device information for multiple terminals from a single source, enabling cross-organization authentication while simplifying management through template reuse.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent creates a universal device information structure that can serve multiple terminals and organizations simultaneously. The device information issued by the certificate issuing device is designed to be universally applicable across different terminals and organizational boundaries, eliminating the need for separate certificate management for each device while enabling broad adaptability for cross-organization authentication scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11522849B2Authentication system and computer readable medium
Publication Date: 2022.12.06 MITSUBISHI ELECTRIC CORP
  • US11522849B2 patent drawing
  • US11522849B2 patent drawing
  • US11522849B2 patent drawing

AI summary

In an authentication system (120) of a first organization that a first user belongs to, when the first user accesses a service of another organization from a user terminal of the first organization, an authentication device (300) receives a hello message from another organization system, encrypts the hello message using a client private key of the first user, and sends the encrypted hello message to said another organization system as a signature message.