Server-Mediated Bluetooth Pairing for Secure Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication methods between a server and an authenticator via Bluetooth pairing are insecure, as the encrypting key obtained during negotiation is not adequately protected, leading to potential data theft.
Innovation Solution
A method and system that involve a client, a server, and an authenticator, where the server generates session data using a stored negotiated key and sends it to the client, enabling the client and authenticator to build a Bluetooth pairing connection and perform bidirectional broadcast and scanning authentication. An encrypting key is generated using the session key after successful authentication, ensuring data encryption during transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the encrypting key is stored at the client for data transmission, then communication convenience is improved, but data security deteriorates as the key may be stolen
Solution Approach 1:
The patent extracts the encrypting key from the client device and relocates it to the server for storage. The server generates and retains the encrypting key, while the client only stores a hash value of the key. This extraction eliminates the security vulnerability of key storage at the client while maintaining communication functionality through the server-mediated key management system.
Solution Approach 2:
The patent introduces a server as an intermediary between the client and the encrypting key. The server acts as a mediator that generates, stores, and manages the encrypting key, while the client communicates with the server to obtain necessary authentication information without directly storing the key. This intermediary structure resolves the contradiction by centralizing key management for security while enabling convenient client-side communication.
2Adaptability or versatility
If the encrypting key is obtained through negotiation between authenticator and client, then key generation flexibility is improved, but security deteriorates because the seed key must be stored at the client
Solution Approach 1:
The patent extracts the seed key from the client device and relocates it to the server for storage. The server generates the seed key and retains it securely, while the client only stores a hash value. This extraction maintains the flexibility of negotiated key generation while eliminating the security risk of storing the actual seed key at the client.
Solution Approach 2:
The server acts as an intermediary that manages the seed key and facilitates key generation. The client and authenticator negotiate keys through the server, which provides the necessary key material without requiring the client to store the actual seed key. This intermediary approach preserves negotiation flexibility while centralizing secure key management.
3Productivity
If data is transmitted in ciphertext using a stored encrypting key, then communication efficiency is improved, but security deteriorates as the stored key becomes a vulnerability
Solution Approach 1:
The patent extracts the encrypting key from client storage and relocates it to server storage. The client communicates efficiently using encryption/decryption operations without the performance penalty of secure key storage, while the server centrally manages the key security. This extraction maintains communication efficiency while eliminating the security vulnerability of client-side key storage.
Data Source
AI summary
A method for communication between a server and an authenticator. The method comprises: a server generating a first client identifier, a first authenticator identifier and a first session key according to a request sent by a client, and broadcasting, by means of the client, data comprising the first client identifier; an authenticator scanning the broadcast data, acquiring a third key to verify the first client identifier, if verification is successful, generating a second authenticator identifier and a second session key, making a notification of the successful verification, stopping scanning, and broadcasting broadcast data comprising the second authenticator identifier; the client stopping broadcasting, and scanning the broadcast data sent by the authenticator, acquiring and verifying the second authenticator identifier in the broadcast data, and if verification is successful, establishing a Bluetooth connection with the authenticator; and the client performing handshake and encrypted communication operation with the authenticator. By means of the present invention, data not being stolen during a transmission process can be ensured, thereby improving the data security during the transmission process, and ensuring the interests of a user.


