Mutual Symmetric Authentication for Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Public Key Infrastructure (PKI) technologies for mutual authentication are expensive, slow, and vulnerable to quantum computing due to their reliance on asymmetric cryptography.
Innovation Solution
A method for mutual symmetric authentication between applications using dynamically generated symmetric keys, where servers within a distributed trust chain exchange master symmetric keys and derive symmetric keys on the fly, enabling fast and secure verification without the need for pre-configured keys at manufacturing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Public Key Infrastructure (PKI) technology is used for mutual authentication, then authentication security is provided, but implementation cost becomes very expensive
Solution Approach 1:
The patent changes the cryptographic parameter from asymmetric keys (PKI) to symmetric keys. Each application receives a unique symmetric key from its hosting server, eliminating the need for expensive certificate authorities and key pair management infrastructure while maintaining authentication security
Solution Approach 2:
The patent extracts the authentication verification process from the manufacturing stage to the runtime stage. Instead of pre-configuring devices with certificates at manufacturing, the system dynamically provides symmetric keys to applications when they are hosted on servers, reducing manufacturing complexity and cost
2Reliability
If Public Key Infrastructure (PKI) technology is used for mutual authentication, then authentication is performed, but processing speed becomes very slow
Solution Approach 1:
The patent changes the cryptographic operation from computationally intensive asymmetric encryption/decryption to much faster symmetric encryption/decryption operations. The symmetric keys enable rapid authentication processing while maintaining security, directly addressing the speed bottleneck of PKI
Solution Approach 2:
The patent performs preliminary key distribution by providing each application with its symmetric key when it is hosted on a server. This pre-establishment of keys eliminates the need for real-time certificate verification and heavy cryptographic processes during authentication, significantly speeding up the process
3Reliability
If asymmetric cryptography is used for authentication, then mutual authentication is achieved, but resistance to quantum computing is lost
Solution Approach 1:
The patent changes the cryptographic algorithm type from asymmetric to symmetric. Symmetric cryptography algorithms are generally considered more resistant to quantum computing attacks compared to asymmetric algorithms, which are vulnerable to Shor's algorithm. This parameter change directly addresses quantum vulnerability while preserving authentication functionality
Solution Approach 2:
The patent uses disposable symmetric keys that are provided to applications temporarily when they are hosted. These keys can be rotated and regenerated easily, providing forward secrecy and limiting the impact of potential quantum attacks, as compromised keys can be discarded without affecting the underlying system security
Data Source
AI summary
A first server exchanges with a second server a master (symmetric) key(s). The first server sends to the first application the master key(s). The second server generates dynamically a first derived key by using a generation parameter(s) and a first master key. The second server sends to the second application the first derived key and the generation parameter(s). The second application generates and sends to the first application a first (key possession) proof and the generation parameter(s). The first application verifies successfully by using the generation parameter(s), the first master key and the first proof, that the first proof has been generated by using the first derived key, generates and sends to the second application a second (key possession) proof. The second application verifies successfully that the second proof has been generated by using the first derived key, as a dynamically generated and proven shared key.

