Spatial Broadcasting Authentication via Namespace Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems struggle to consistently and accurately determine the legitimacy of broadcast messages from spatial devices, as they may incorrectly reject legitimate messages intentionally broadcast over long distances.

Innovation Solution

An authentication service utilizing a third-party server to generate and manage authentication certificates and public keys for named entity devices, allowing policy consuming devices to validate messages using public key authentication and DNSSEC.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional systems perform time and location checks to detect manipulated messages, then message security is improved, but legitimate messages broadcast over long distances are incorrectly rejected

Engineering Contradiction:
Improvemessage legitimacy determinationVSAvoidmessage reception range
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a namespace server as an intermediary between the broadcasting device and the receiving device. The namespace server stores and provides authentication certificates that contain public keys. The receiving device uses these public keys to authenticate messages without needing to verify time and location constraints, thus resolving the contradiction between message security and long-distance reception capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical time and location verification system with a cryptographic authentication system based on public key infrastructure. Instead of checking temporal and spatial parameters, the system uses digital certificates and public key cryptography to verify message authenticity, enabling long-distance message reception while maintaining security

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If conventional systems use time and location verification, then spoofing detection is improved, but system complexity increases due to continuous verification requirements

Engineering Contradiction:
Improvespoofing detectionVSAvoidverification process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-distributing authentication certificates containing public keys through a namespace server before message broadcasting. This eliminates the need for continuous time and location verification during message reception, reducing system complexity while maintaining spoofing detection capability through cryptographic authentication

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent substitutes the complex mechanical verification process (continuous time and location checking) with a simpler cryptographic verification process using public keys from authentication certificates. This reduces computational overhead and system complexity while maintaining or improving spoofing detection reliability

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12294662B2Spatial broadcasting device authentication
Publication Date: 2025.05.06 VALIMAIL INC
  • US12294662B2 patent drawing
  • US12294662B2 patent drawing
  • US12294662B2 patent drawing

AI summary

Embodiments relate to systems for generating identity records (e.g., authentication certificates) at a server for validating broadcast messages. The server may receive a request to generate an identity record, where the request may include a public key of a named entity device that is configured to broadcast messages. The server may generate the identity record using the private key of the server and transmit the generated certificate to a namespace server for storage. A policy consuming device configured to receive a broadcast message, which may be signed using the private key of the named entity device, subsequently accesses the namespace server for the identity record including the public key of the named entity device. The policy consuming device validates the authentication certificate using the server's public key and validates the broadcast message using the named entity device's public key.