Mutual Symmetric Authentication for Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Public Key Infrastructure (PKI) technologies for mutual authentication are expensive, slow, and vulnerable to quantum computing due to their reliance on asymmetric cryptography.

Innovation Solution

A method for mutual symmetric authentication between applications using dynamically generated symmetric keys, where servers within a distributed trust chain exchange master symmetric keys and derive symmetric keys on the fly, enabling fast and secure verification without the need for pre-configured keys at manufacturing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Public Key Infrastructure (PKI) technology is used for mutual authentication, then authentication security is provided, but implementation cost becomes very expensive

Engineering Contradiction:
Improveauthentication securityVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent changes the cryptographic parameter from asymmetric keys (PKI) to symmetric keys. Each application receives a unique symmetric key from its hosting server, eliminating the need for expensive certificate authorities and key pair management infrastructure while maintaining authentication security

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent extracts the authentication verification process from the manufacturing stage to the runtime stage. Instead of pre-configuring devices with certificates at manufacturing, the system dynamically provides symmetric keys to applications when they are hosted on servers, reducing manufacturing complexity and cost

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If Public Key Infrastructure (PKI) technology is used for mutual authentication, then authentication is performed, but processing speed becomes very slow

Engineering Contradiction:
Improveauthentication capabilityVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent changes the cryptographic operation from computationally intensive asymmetric encryption/decryption to much faster symmetric encryption/decryption operations. The symmetric keys enable rapid authentication processing while maintaining security, directly addressing the speed bottleneck of PKI

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent performs preliminary key distribution by providing each application with its symmetric key when it is hosted on a server. This pre-establishment of keys eliminates the need for real-time certificate verification and heavy cryptographic processes during authentication, significantly speeding up the process

Inventive Principle:
Principle #10Preliminary action

3Reliability

If asymmetric cryptography is used for authentication, then mutual authentication is achieved, but resistance to quantum computing is lost

Engineering Contradiction:
Improveauthentication functionalityVSAvoidquantum computing vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the cryptographic algorithm type from asymmetric to symmetric. Symmetric cryptography algorithms are generally considered more resistant to quantum computing attacks compared to asymmetric algorithms, which are vulnerable to Shor's algorithm. This parameter change directly addresses quantum vulnerability while preserving authentication functionality

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent uses disposable symmetric keys that are provided to applications temporarily when they are hosted. These keys can be rotated and regenerated easily, providing forward secrecy and limiting the impact of potential quantum attacks, as compromised keys can be discarded without affecting the underlying system security

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS11196722B2Method for mutual symmetric authentication between a first application and a second application
Publication Date: 2021.12.07 THALES DIS CPL CANADA INC
  • US11196722B2 patent drawing
  • US11196722B2 patent drawing

AI summary

A first server exchanges with a second server a master (symmetric) key(s). The first server sends to the first application the master key(s). The second server generates dynamically a first derived key by using a generation parameter(s) and a first master key. The second server sends to the second application the first derived key and the generation parameter(s). The second application generates and sends to the first application a first (key possession) proof and the generation parameter(s). The first application verifies successfully by using the generation parameter(s), the first master key and the first proof, that the first proof has been generated by using the first derived key, generates and sends to the second application a second (key possession) proof. The second application verifies successfully that the second proof has been generated by using the first derived key, as a dynamically generated and proven shared key.