Tamper-Resistant Signature for Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Digital Rights Management (DRM) systems in communication networks are insecure as devices can falsely claim support for DRM specifications, allowing unauthorized terminals to receive and misuse protected content.

Innovation Solution

Incorporating a tamper-resistant signature into device-type associated commitment headers to ensure authenticity, which is verified by the content provider before accepting the commitment, using protocols like HTTP or SMTP.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If device-type associated commitment headers are used without signature verification, then ease of operation is improved, but reliability deteriorates as devices can falsely claim DRM support

Engineering Contradiction:
Improvedevice authenticationVSAvoidauthenticity of device commitment
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-configuring tamper-resistant signature generation capabilities in the receiving device before authentication occurs. The device creates a signature based on its hardware identity and device-type specific information in advance, which is then included in the commitment header. This preliminary signature creation ensures that when authentication occurs, the device can immediately provide verified proof of its identity without requiring complex real-time verification procedures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses a signature as an intermediary element between the device and content provider. Instead of direct trust or complex mutual authentication protocols, the device generates a signature that serves as a verifiable intermediary proof of its identity and commitment. The content provider verifies this signature to confirm device authenticity, eliminating the need for extensive signaling while maintaining high reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If signature verification is implemented for device authentication, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improveauthenticity of device commitmentVSAvoidauthentication mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex signature verification logic from the receiving device and places it in the content provider's authentication system. The receiving device only needs to generate and include its signature in the commitment header, which is a relatively simple operation. The content provider performs the verification against its database of device identities and DRM capabilities, centralizing the complexity in the server rather than the client device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the authentication parameters from requiring extensive signaling and multiple verification steps to using a compact signature included in the device-type associated commitment header. This parameter change reduces the computational and communication overhead in the device while maintaining verification reliability through cryptographic signature validation.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If extensive signaling efforts are used for device authentication, then reliability is improved, but loss of time increases

Engineering Contradiction:
Improvedevice authenticationVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring the device with its hardware identity and device-type specific information that will be used for signature generation. This preparation is done once during device setup, and then the actual authentication process only requires generating and transmitting the signature, significantly reducing the time required for authentication while maintaining reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables the authentication process to skip extensive back-and-forth signaling by using a self-contained signature in the commitment header. The content provider can verify the signature directly without requiring multiple verification rounds or additional signaling messages, allowing the authentication to be completed rapidly in a single verification step.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS7509496B2Device-type authentication in communication systems
Publication Date: 2009.03.24 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US7509496B2 patent drawing
  • US7509496B2 patent drawing
  • US7509496B2 patent drawing

AI summary

In a communication system (1), a header comprising information, preferably being related with a device-type associated commitment, is additionally provided with a signature for that information. The signature guarantees the authenticity of the header information. The signature is tamper-resistantly created in a first device (20), preferably based on at least tamper-resistant device-type specific information of the first device (20). The header information and the signature are communicated to a content provider (10), where the signature is verified before accepting the device-type associated commitment to be valid. Such signatures can preferably be used in systems using HTTP or SMTP.