Symmetric Decryption Key Generation for Secure ID Checking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing emergency response systems face challenges in quickly validating the credentials and privileges of first responders during emergencies, and current encryption methods like public key encryption are costly and not cost-effective for high-volume user scenarios.

Innovation Solution

A method and apparatus for secure ID checking using symmetric decryption keys generated from information on secure cards to decrypt encrypted attribute information, allowing for efficient protection and validation of access to secure areas without requiring real-time network connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If public key encryption is used to protect attribute information transmission, then security is improved, but cost and administrative complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the expensive public key encryption step and replaces it with symmetric encryption for the actual attribute information transmission. Public key infrastructure is used only for key exchange, while symmetric encryption handles the bulk data protection, significantly reducing administrative complexity while maintaining security

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces symmetric encryption keys as an intermediary mechanism. These keys enable efficient encrypted communication between access control devices and credential database without requiring full public key infrastructure for every transmission, reducing both cost and complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If public key encryption is used to protect attribute information transmission, then security is improved, but cost effectiveness deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidcost effectiveness
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent uses symmetric encryption keys that can be generated, distributed, and discarded more easily and cheaply than public key infrastructure. These temporary symmetric keys provide sufficient security for attribute information transmission without the high costs associated with public key certificate management and validation

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If a secure hardwired transmission line is used to protect attribute information, then security is improved, but cost effectiveness and adaptability deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the encryption parameter from requiring physical secure channels to using cryptographic protection over existing communication channels. This allows the system to work over wireless and network connections while maintaining security through proper encryption and key management

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8099603B2Secure ID checking
Publication Date: 2012.01.17 ASSA ABLOY AB
  • US8099603B2 patent drawing
  • US8099603B2 patent drawing
  • US8099603B2 patent drawing

AI summary

A cost-effective system that provides for the efficient protection of transmitted non-public attribute information may be used, for example, to control access to a secure area. Encryption of the attribute information may be performed using symmetric encryption techniques, such as XOR and/or stream cipher encryption. A centralized database that stores and transmits the encrypted attribute information may generate the encryption/decryption key based on selected information bytes, for example, as taken from a card inserted into a handheld device used at the secure area. The selected information to generate the encryption key stream may be varied on a periodic basis by the centralized database. Information as to which selected bytes are to be used for a particular access authorization request may be transmitted to the handheld unit or may be input through action of a user of the handheld unit, for example by entry of a PIN code.