Symmetric Dynamic Authentication Key Exchange System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional information security authentication systems are vulnerable to attacks when certification authorities are compromised, and they lack dynamic key updates, leading to potential information breaches and inefficient error handling through automatic repeat requests, which burden networks and waste time.
Innovation Solution
A symmetric dynamic authentication and key exchange system where a client and server generate and update temporary authentication information and keys, enabling advanced identity verification and secure communication through a network, with the client and server confirming identities and updating keys dynamically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a 3rd party certification authority is used to provide public and private keys for encryption/decryption, then information transfer confidentiality is ensured, but the system becomes vulnerable to attacks when the certification authority is compromised and certification data is leaked
Solution Approach 1:
The patent extracts the authentication function from the 3rd party certification authority and implements it locally in the authentication system. The system generates authentication information locally without relying on external certification authorities, thereby eliminating the vulnerability associated with centralized key management while maintaining information transfer confidentiality.
Solution Approach 2:
The patent introduces an authentication information generation mechanism that acts as an intermediary between communication parties. This mechanism generates and manages authentication information locally, replacing the traditional 3rd party certification authority as the mediator, thus eliminating the security vulnerability while preserving the confidentiality function.
2Ease of operation
If fixed encryption/decryption keys are obtained from the certification authority, then information can be encrypted and decrypted, but the information loses confidentiality when skimmed and cracked through brute force attack or symmetric key algorithm
Solution Approach 1:
The patent implements dynamic authentication information that changes with each authentication session. Instead of using fixed encryption/decryption keys, the system generates different authentication information for each session, making brute force attacks ineffective as the keys are not static but dynamically updated based on session-specific parameters.
Solution Approach 2:
The patent changes the parameters of authentication information dynamically during different authentication sessions. The authentication information is generated based on varying parameters such as session identifiers and timestamps, ensuring that even if one session's credentials are compromised, they cannot be used to crack other sessions, thereby protecting against brute force attacks.
3Reliability
If an automatic repeat request fault-tolerant mechanism is implemented, then erroneous transferred information can be corrected, but the network burden increases and lots of time is wasted
Solution Approach 1:
The patent incorporates error detection and correction codes in the authentication information before transmission. By performing preliminary error prevention measures during the authentication information generation and encoding phase, the system can detect and correct transmission errors without requiring repeated requests, thus reducing network burden and time loss while maintaining reliability.
Data Source
AI summary
A symmetric dynamic authentication and key exchange system and a method thereof are provided. A client and a server obtain initial authentication information at the same time, the client generates first one-time temporary authentication information, a conference key and a standby identity identifier according to the initial authentication information, and transmits them to the server, and the server performs a dynamic authentication program. The server compares the initial authentication information of the client with the conference key to confirm an identity of the client, and then updates the initial authentication information of the server according to the first one-time temporary authentication information, and the server is enabled to have the first one-time temporary authentication information the same as that of the client, and then to generate second one-time temporary authentication information including the standby identity identifier according to the first one-time temporary authentication information and the initial authentication information.


