Secure D2D Authentication via Time-Synchronized IDA

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems face challenges in securely authenticating device identification and user identification for low throughput device-to-device communications, particularly in scenarios with limited bandwidth and high overhead, where traditional authentication methods may compromise security due to repeatability and overhead concerns.

Innovation Solution

The implementation of a method that involves pairing devices for a limited duration, sharing a secret key, time synchronizing them, and generating a reduced-length identification discovery advertisement (IDA) using a shared secret, which is encrypted and transmitted, allowing for secure authentication without relying on higher layer functionality, thus minimizing overhead and maintaining security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used for device-to-device communication, then authentication can be performed, but security is compromised due to repeatability and overhead concerns in low throughput environments

Engineering Contradiction:
Improveauthentication securityVSAvoidrepeatability risk and overhead
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent applies dynamics by making the authentication mechanism time-dependent and session-specific. The identification discovery advertisement includes a timestamp and is valid only for a limited duration, preventing reuse across different time periods. The shared secret is refreshed for each pairing session, ensuring that authentication credentials are dynamic rather than static, thereby eliminating repeatability attacks while maintaining security in low throughput environments.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of the authentication mechanism by using a reduced-length identification discovery advertisement that is encrypted with a shared secret. The advertisement includes modified parameters such as timestamp, validity duration, and encrypted content, which change with each authentication attempt. This parameter transformation ensures that even if the advertisement is captured, it cannot be reused, addressing the repeatability issue while reducing overhead through efficient parameter encoding.

Inventive Principle:
Principle #35Parameter changes

2Quantity of substance

If a reduced-length identification discovery advertisement is used, then overhead is minimized for low throughput communication, but authentication security must be maintained through alternative means

Engineering Contradiction:
Improvedata transmission overheadVSAvoidauthentication security
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent extracts only the essential authentication information needed for security verification, removing unnecessary data from the identification discovery advertisement. By taking out only the critical elements (timestamp, encrypted shared secret portion, validity indicator) and transmitting only these minimal required parameters, the system achieves reduced overhead while maintaining authentication security through the encrypted core content that proves identity without requiring large data transfers.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent employs disposable authentication credentials that are valid only for a limited time and then discarded. The identification discovery advertisement is generated with a specific validity duration and is not reused after expiration. This disposable approach allows the use of reduced-length advertisements because each short-lived credential is independently valid and cannot be reused, maintaining security while minimizing the data quantity needed for each authentication event.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If devices are paired for limited duration with shared secret, then security against repeatability is improved, but time synchronization complexity increases

Engineering Contradiction:
Improvesecurity against repeatabilityVSAvoidtime synchronization mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by establishing time synchronization and shared secret generation during the pairing setup phase before actual data communication begins. The timestamp and validity duration are predetermined and configured during pairing, so that during normal operation, the devices only need to verify these pre-established parameters rather than continuously managing complex synchronization. This preliminary configuration simplifies the ongoing synchronization burden while maintaining security against repeatability attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses periodic action through the limited duration validity mechanism, where authentication credentials are refreshed periodically for each pairing session. Instead of continuous complex synchronization, the system uses periodic validation of timestamps and validity periods that are checked at discrete authentication moments. This periodic verification approach maintains security against repeatability while reducing the continuous complexity of time synchronization to simple timestamp comparisons at each authentication event.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10666628B2Secure authentication of device identification for low throughput device to-device wireless communication
Publication Date: 2020.05.26 APPLE INC
  • US10666628B2 patent drawing
  • US10666628B2 patent drawing
  • US10666628B2 patent drawing

AI summary

Systems, methods, and computer-readable media may be provided for securely authenticating device identification and/or user identification for low throughput device-to-device wireless communication.