Secure Mobile Device Contact via Cryptographic Key Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for coupling mobile devices with transportation vehicles via WLAN or Bluetooth LE lack security without direct access to the vehicle and pre-configuration, making them vulnerable to man-in-the-middle attacks, especially in car-sharing systems where no out-of-band confirmation is possible.
Innovation Solution
A method using symmetric or asymmetric keys introduced by a trusted entity for secure initial contact, involving key exchange, signature generation, and cryptographic verification to authenticate devices without needing direct access to the vehicle or a central server, preventing man-in-the-middle attacks and allowing any device to be used as a digital key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If existing coupling methods (WLAN/Bluetooth) are used without direct access and pre-configuration, then device connectivity is achieved, but security is compromised due to vulnerability to man-in-the-middle attacks
Solution Approach 1:
The patent applies preliminary action by pre-distributing cryptographic keys (such as Bluetooth Low Energy pairing keys or WLAN WPA-2 pre-shared keys) to mobile devices through a trusted entity before the devices need to connect. This allows secure connections to be established without requiring direct access to the transportation vehicle or pre-configuration of the specific device pair, while maintaining security through cryptographic verification. The key distribution happens in advance through authorized channels, enabling secure first-time connections.
2Reliability
If cryptographic verification is implemented for secure connections, then security is improved, but complexity of the connection process increases
Solution Approach 1:
The patent applies self-service by enabling mobile devices to autonomously perform cryptographic verification using pre-distributed keys. The mobile device independently verifies the transportation vehicle's identity by checking cryptographic signatures or performing key exchange protocols without requiring manual intervention, external servers, or complex user procedures. This automation maintains high security while reducing operational complexity for the user.
3Reliability
If out-of-band confirmation is required for authentication, then security is improved, but ease of operation deteriorates due to need for direct access and manual confirmation
Solution Approach 1:
The patent replaces the mechanical out-of-band confirmation method (manual comparison of display codes or PINs) with electronic cryptographic verification. Instead of requiring users to manually compare codes displayed on both devices, the system uses pre-distributed cryptographic keys and automated signature verification to authenticate the transportation vehicle. This substitution maintains strong authentication security while eliminating the need for direct physical access to the vehicle and manual user confirmation steps.
Data Source
AI summary
A method providing security the first time a mobile device makes contact with a device including a trusted entity introducing asymmetric key into a mobile device, performing a key exchange method on contact-making resulting in a shared key in the mobile device and in the device, generating a first signature with the symmetric key using the shared key in the mobile device, generating a second signature with the symmetric key using the shared key in the device, transmitting the first signature to the device and the second signature to the mobile device, authenticating the device by cryptographic verification of the second signature with the symmetric key in the mobile device, authenticating the mobile device by cryptographic verification of the first signature with the symmetric key in the device, and continuing contact-making in the event of mutual successful authentication or termination of contact-making if at least one authentication has failed.


