Spatial Broadcasting Authentication via Namespace Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems struggle to consistently and accurately determine the legitimacy of broadcast messages from spatial devices, as they may incorrectly reject legitimate messages intentionally broadcast over long distances.
Innovation Solution
An authentication service utilizing a third-party server to generate and manage authentication certificates and public keys for named entity devices, allowing policy consuming devices to validate messages using public key authentication and DNSSEC.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional systems perform time and location checks to detect manipulated messages, then message security is improved, but legitimate messages broadcast over long distances are incorrectly rejected
Solution Approach 1:
The patent introduces a namespace server as an intermediary between the broadcasting device and the receiving device. The namespace server stores and provides authentication certificates that contain public keys. The receiving device uses these public keys to authenticate messages without needing to verify time and location constraints, thus resolving the contradiction between message security and long-distance reception capability
Solution Approach 2:
The patent replaces the mechanical time and location verification system with a cryptographic authentication system based on public key infrastructure. Instead of checking temporal and spatial parameters, the system uses digital certificates and public key cryptography to verify message authenticity, enabling long-distance message reception while maintaining security
2Reliability
If conventional systems use time and location verification, then spoofing detection is improved, but system complexity increases due to continuous verification requirements
Solution Approach 1:
The patent implements preliminary action by pre-distributing authentication certificates containing public keys through a namespace server before message broadcasting. This eliminates the need for continuous time and location verification during message reception, reducing system complexity while maintaining spoofing detection capability through cryptographic authentication
Solution Approach 2:
The patent substitutes the complex mechanical verification process (continuous time and location checking) with a simpler cryptographic verification process using public keys from authentication certificates. This reduces computational overhead and system complexity while maintaining or improving spoofing detection reliability
Data Source
AI summary
Embodiments relate to systems for generating identity records (e.g., authentication certificates) at a server for validating broadcast messages. The server may receive a request to generate an identity record, where the request may include a public key of a named entity device that is configured to broadcast messages. The server may generate the identity record using the private key of the server and transmit the generated certificate to a namespace server for storage. A policy consuming device configured to receive a broadcast message, which may be signed using the private key of the named entity device, subsequently accesses the namespace server for the identity record including the public key of the named entity device. The policy consuming device validates the authentication certificate using the server's public key and validates the broadcast message using the named entity device's public key.


