Remote Device Authentication via Challenge-Response Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems face challenges in securely and reliably verifying the identity of devices, particularly in remote scenarios, where abuse can occur if the system cannot determine ink usage or service requests accurately, leading to potential harm to genuine clients.

Innovation Solution

A method for remotely authenticating devices using generated authentication data and secret key data, where symmetric or asymmetric key cryptography is employed to ensure secure communication between devices and a remote authentication engine, with challenge-response pairs used to verify device identity, and public or private keys used to authenticate without pre-stored data, allowing for secure and scalable authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication mechanisms are used, then device identity verification can be achieved, but the system becomes vulnerable to abuse and cannot reliably determine service usage

Engineering Contradiction:
Improvedevice authentication reliabilityVSAvoidabuse vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by performing authentication before allowing any service transactions. The authentication engine verifies the device's identity and entitlements in advance, ensuring that only authenticated devices can subsequently access services. This prevents abuse by establishing trust before any potential harmful actions can occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication engine as an intermediary between the device and the service provisioning system. This intermediary component verifies device identity and manages authentication state, creating a layer of protection that prevents direct abuse while maintaining reliable authentication. The intermediary handles authentication decisions centrally, ensuring consistency and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If pre-stored authentication data is used, then authentication can be performed, but the system becomes more complex and less scalable

Engineering Contradiction:
Improveauthentication implementation simplicityVSAvoidauthentication system complexity
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The patent extracts the authentication data storage function from the device itself and relocates it to a centralized authentication engine. Instead of storing authentication data locally in devices (which increases device complexity and manufacturing difficulty), the system stores authentication state remotely and retrieves it only when needed for verification, simplifying both device design and system architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication engine serves multiple functions: it authenticates devices, manages authentication state, and controls service access. By consolidating these functions in a single universal component rather than requiring separate authentication mechanisms in each device, the system reduces overall complexity while maintaining ease of implementation through standardized authentication protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If secure key management is implemented, then authentication security is improved, but the cost and complexity of the system increases

Engineering Contradiction:
Improveauthentication securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication engine acts as an intermediary that manages cryptographic key operations centrally. Rather than requiring each device to implement complex key management systems, the authentication engine handles key distribution, storage, and verification, improving security while reducing device complexity. The intermediary consolidates security functions that would otherwise need to be replicated across all devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses cryptographic copying mechanisms where authentication data is transmitted in an encrypted form from the authentication engine to devices. Instead of sharing actual keys (which would increase complexity and security risks), the system transmits encrypted authentication data that can be decrypted only by the authenticated device, maintaining security while simplifying key management through standardized cryptographic protocols.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9882899B2Remotely authenticating a device
Publication Date: 2018.01.30 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US9882899B2 patent drawing
  • US9882899B2 patent drawing
  • US9882899B2 patent drawing

AI summary

Remotely authenticating a device includes generating authentication data and secret key data in a controlled environment, sending the authentication data to a remote authentication engine, and sending the secret key data to a personalization engine to apply the secret key data to a device after sending the authentication data to the remote authentication engine such that the remote authentication engine has an ability to authenticate the device.