Session Key Derivation via Challenge-Response Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems fail to simultaneously secure both devices and data, particularly in wireless communications, where 'man-in-the-middle' attacks can intercept and alter data even after device authentication, and conventional solutions rely on secret keys that are vulnerable to interception.

Innovation Solution

Implementing a challenge-response protocol using elliptic curve asymmetric authentication to derive a session key known to both devices, which is used for authenticating devices and securing data exchanges, thereby preventing 'man-in-the-middle' attacks and ensuring data integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication systems are used, then device authentication can be achieved, but data security is compromised due to vulnerability to man-in-the-middle attacks

Engineering Contradiction:
Improvedevice authenticationVSAvoiddata interception and manipulation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent merges device authentication and data authentication into a single integrated system. The authentication device performs both functions simultaneously: authenticating the identity of communication devices and authenticating data packets during transmission. This eliminates the security gap where device authentication occurred but data remained vulnerable to interception.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an intermediary authentication mechanism using challenge-response protocols and session keys. The authentication device acts as a mediator that establishes secure communication channels, generates session-specific keys, and verifies data integrity before allowing data transmission, thereby preventing man-in-the-middle attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secret keys are used for authentication, then authentication security can be maintained, but the keys become vulnerable to interception and compromise

Engineering Contradiction:
Improveauthentication securityVSAvoidkey interception
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent transitions from static secret keys to dynamic session keys that are generated on-demand during each authentication session. The challenge-response protocol creates unique session-specific keys that change with each communication, making intercepted keys useless for subsequent attacks. This dynamic key generation eliminates the vulnerability of persistent secret keys.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent performs preliminary authentication actions before data transmission begins. The challenge-response protocol establishes trust and generates secure session keys in advance, creating a secure foundation before any actual data communication occurs. This preliminary security setup prevents key interception during data transmission.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If separate authentication mechanisms are used for devices and data, then each function can be optimized, but system complexity increases

Engineering Contradiction:
Improveauthentication functionalityVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines device authentication and data authentication into a single integrated authentication device and protocol suite. The same authentication device handles both functions, and the challenge-response protocol simultaneously establishes device identity verification and data integrity protection, eliminating the need for separate complex systems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9450933B2Systems and methods for device and data authentication
Publication Date: 2016.09.20 INFINEON TECHNOLOGIES AG
  • US9450933B2 patent drawing
  • US9450933B2 patent drawing
  • US9450933B2 patent drawing

AI summary

Embodiments relate to systems and methods for authenticating devices and securing data. In embodiments, a session key for securing data between two devices can be derived as a byproduct of a challenge-response protocol for authenticating one or both of the devices.