Tamper-Proof Key Certificate Provision Using One-Time Password Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for securing user devices, such as energy gateways and medical devices, lack a tamper-proof mechanism for providing key certificates, making them vulnerable to unauthorized certification and potential manipulation during the registration process.

Innovation Solution

A method and device that utilize a one-time password (OTP) generated by the service provider's server, linked to a user device's ID, to securely verify a signing request message, ensuring that only the legitimate user device can receive a key certificate, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If key material is sent to the service provider's server for certification in a message without authenticated connection, then the registration process can be completed, but the system becomes vulnerable to unauthorized certification and manipulation

Engineering Contradiction:
Improveregistration processVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by generating and transmitting the one-time password to the user device before the signing request message is sent. This OTP is stored in a data carrier within the user device, establishing an authenticated connection in advance. When the signing request is later transmitted to the server, the server can verify the OTP to ensure the message originates from the legitimate device, thus preventing unauthorized certification while maintaining operational ease.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a one-time password verification mechanism is implemented for signing request messages, then authentication security is enhanced, but the device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidverification mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses an intermediary approach by introducing a data carrier (such as a USB stick or integrated memory) that stores the one-time password. This data carrier acts as a mediator between the user device and the server, containing the authentication credential without requiring complex verification logic in either endpoint. The server simply reads and verifies the OTP from the signing request message, while the user device automatically includes it, thus enhancing security without significantly increasing device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the one-time password is stored in an integrated data carrier in the user device, then tamper-proof provision is achieved, but the ease of manufacture decreases

Engineering Contradiction:
Improvetamper-proof provisionVSAvoiddevice assembly
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent applies the nested doll principle by integrating the data carrier containing the one-time password directly into the user device structure. The data carrier is nested within the device housing, making it a permanent, tamper-resistant part of the device. This integration ensures that the OTP cannot be easily extracted or tampered with, achieving tamper-proof provision. While this slightly complicates manufacturing compared to separate components, it significantly enhances security without requiring complex assembly procedures.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentEP3240227B1Method and device for tamper-proof provision of a key certificate
Publication Date: 2020.04.01 III HOLDINGS 12 LLC
  • EP3240227B1 patent drawingFigure 1~2
  • EP3240227B1 patent drawing
  • EP3240227B1 patent drawing

AI summary

The present invention relates to a method and a server for tamper-proof provision of a key certificate (Z) for a public device key (Kpub) of a user device (1) installed on a user's device by a server (2) of a service provider who provides a service to the user via the user device (1), wherein the server (2) provides the key certificate (Z) to the user device (1) if a signing request message (CSR) received by the user device (1) is successfully verified by the server (2) using a one-time password (OTP) generated for the user device (1) by the server (2).