Resilient Device Authentication via Hierarchical Verification Authorities

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity management and authentication solutions are complex, disparate, and costly, particularly when it comes to deploying hardware biometrics across systems, users, and enterprises, leading to increased operational complexity and security risks.

Innovation Solution

A Resilient Device Authentication (RDA) system that employs hardware biometrics integrated into the manufacturing process, operating systems, and applications, using a hierarchical structure with Verification Authorities, Provisioning Entities, and Device Management Systems to manage authentication and security functions efficiently across diverse applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware biometrics are deployed across systems and enterprises, then device identification and authentication capability is improved, but manufacturing and provisioning costs increase

Engineering Contradiction:
Improvedevice authentication capabilityVSAvoidmanufacturing and provisioning cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent creates virtual copies of hardware biometric capabilities through software-based authentication mechanisms. Instead of requiring physical hardware biometrics in every device, the system uses cryptographic keys and certificates that replicate authentication functionality, significantly reducing manufacturing costs while maintaining security capabilities.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces physical hardware biometric systems with software-based cryptographic mechanisms. By substituting mechanical/physical authentication hardware with digital keys and certificates stored in standard devices, the system eliminates the need for expensive specialized hardware manufacturing while achieving equivalent or superior authentication reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If hardware biometrics are deployed across systems and enterprises, then device identification and authentication capability is improved, but operational complexity increases

Engineering Contradiction:
Improvedevice authentication capabilityVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal authentication framework where a single set of cryptographic primitives (keys, certificates, signing algorithms) serves multiple authentication purposes across different devices, systems, and enterprises. This multi-functional approach eliminates the need for separate hardware biometric systems for each application, reducing operational complexity while maintaining robust authentication capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces trusted third-party intermediaries (certificate authorities, key management services) that manage the complexity of hardware biometric authentication centrally. These intermediaries handle key generation, distribution, and validation, allowing individual devices to perform simple authentication operations without managing the underlying cryptographic complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple disparate authentication technologies are used, then specific application requirements are met, but system complexity and overhead increase

Engineering Contradiction:
Improveapplication-specific authentication capabilityVSAvoidsystem design complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal cryptographic authentication framework that can adapt to various application requirements through configuration rather than architectural complexity. The same core infrastructure (keys, certificates, signing operations) serves diverse applications including device authentication, code signing, and secure communication, eliminating the need for multiple disparate authentication systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent achieves application-specific authentication capabilities by changing cryptographic parameters (key lengths, algorithms, certificate formats) rather than changing the fundamental authentication architecture. This allows the system to adapt to different security requirements and application needs while maintaining a single, manageable system design.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9258129B2Resilient device authentication system
Publication Date: 2016.02.09 ANALOG DEVICES INC
  • US9258129B2 patent drawing
  • US9258129B2 patent drawing
  • US9258129B2 patent drawing

AI summary

A resilient device authentication system comprising: one or more verification authorities (VAs) including a memory loaded with a complete verification set that includes hardware part-specific data, and configured to create a limited verification set (LVS) therefrom; one or more provisioning entities (PEs) each connectable to at least one of the VAs, including a memory loaded with a LVS, and configured to select a subset of data therefrom so as to create an application limited verification set (ALVS). Also disclosed is a device for use with an authentication system, comprising: a first hardware part and a second hardware part that are adapted to communicate with and perform authentication on each other; and/or a hardware part that contains two or more chips that are adapted to communicate with and perform authentication on each other.