Symmetric Dynamic Authentication Key Exchange System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional information security authentication systems are vulnerable to attacks when certification authorities are compromised, and they lack dynamic key updates, leading to potential information breaches and inefficient error handling through automatic repeat requests, which burden networks and waste time.

Innovation Solution

A symmetric dynamic authentication and key exchange system where a client and server generate and update temporary authentication information and keys, enabling advanced identity verification and secure communication through a network, with the client and server confirming identities and updating keys dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a 3rd party certification authority is used to provide public and private keys for encryption/decryption, then information transfer confidentiality is ensured, but the system becomes vulnerable to attacks when the certification authority is compromised and certification data is leaked

Engineering Contradiction:
Improveinformation transfer confidentialityVSAvoidvulnerability to attacks when certification authority is compromised
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication function from the 3rd party certification authority and implements it locally in the authentication system. The system generates authentication information locally without relying on external certification authorities, thereby eliminating the vulnerability associated with centralized key management while maintaining information transfer confidentiality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an authentication information generation mechanism that acts as an intermediary between communication parties. This mechanism generates and manages authentication information locally, replacing the traditional 3rd party certification authority as the mediator, thus eliminating the security vulnerability while preserving the confidentiality function.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If fixed encryption/decryption keys are obtained from the certification authority, then information can be encrypted and decrypted, but the information loses confidentiality when skimmed and cracked through brute force attack or symmetric key algorithm

Engineering Contradiction:
Improveencryption/decryption capabilityVSAvoidinformation confidentiality against brute force attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic authentication information that changes with each authentication session. Instead of using fixed encryption/decryption keys, the system generates different authentication information for each session, making brute force attacks ineffective as the keys are not static but dynamically updated based on session-specific parameters.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of authentication information dynamically during different authentication sessions. The authentication information is generated based on varying parameters such as session identifiers and timestamps, ensuring that even if one session's credentials are compromised, they cannot be used to crack other sessions, thereby protecting against brute force attacks.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If an automatic repeat request fault-tolerant mechanism is implemented, then erroneous transferred information can be corrected, but the network burden increases and lots of time is wasted

Engineering Contradiction:
Improveerror correction capabilityVSAvoidtime wasted in repeat requests
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent incorporates error detection and correction codes in the authentication information before transmission. By performing preliminary error prevention measures during the authentication information generation and encoding phase, the system can detect and correct transmission errors without requiring repeated requests, thus reducing network burden and time loss while maintaining reliability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8972734B2Symmetric dynamic authentication and key exchange system and method thereof
Publication Date: 2015.03.03 NAT SUN YAT SEN UNIV
  • US8972734B2 patent drawing
  • US8972734B2 patent drawing
  • US8972734B2 patent drawing

AI summary

A symmetric dynamic authentication and key exchange system and a method thereof are provided. A client and a server obtain initial authentication information at the same time, the client generates first one-time temporary authentication information, a conference key and a standby identity identifier according to the initial authentication information, and transmits them to the server, and the server performs a dynamic authentication program. The server compares the initial authentication information of the client with the conference key to confirm an identity of the client, and then updates the initial authentication information of the server according to the first one-time temporary authentication information, and the server is enabled to have the first one-time temporary authentication information the same as that of the client, and then to generate second one-time temporary authentication information including the standby identity identifier according to the first one-time temporary authentication information and the initial authentication information.