Terminal Authentication Using Unidirectional Hash Derivation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing terminal authentication methods face challenges in accurately identifying and authenticating client terminals that are targets for client certificates, leading to potential misuse and security vulnerabilities due to difficulties in confirming the authenticity of client terminals.
Innovation Solution
A terminal authentication system that includes a client terminal with a storage unit for secret information and a client certificate with a hash value, and a server device with a unidirectional function processing unit to derive and compare hash values for authentication, ensuring accurate identification and authentication of client terminals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device inherent information is used for encryption key in authentication, then device authentication can be performed, but it is difficult to specify the target client terminal for certificate issuance
Solution Approach 1:
The authentication system segments the identification process into two distinct components: device inherent information (for encryption) and terminal identification information (for target specification). This segmentation allows the encryption key to be derived from device characteristics while separately handling terminal identification, thus resolving the contradiction between authentication reliability and identification precision.
Solution Approach 2:
The patent introduces a new dimension of terminal identification information that operates independently from device inherent information. By adding this additional dimension, the system can maintain authentication reliability through device characteristics while simultaneously achieving precise terminal identification through the separate identification information channel.
2Reliability
If digital certificate authentication is used, then network communication safety is improved, but the authenticity of client terminals cannot be confirmed
Solution Approach 1:
The patent introduces terminal identification information as an intermediary element that bridges the gap between digital certificate authentication and client terminal authenticity verification. This intermediary carries specific terminal identification data that enables the server to verify the authenticity of the client terminal while maintaining the security benefits of digital certificate authentication.
Solution Approach 2:
The system performs preliminary embedding of terminal identification information in the client terminal before authentication occurs. This preliminary action ensures that the terminal identification data is already prepared and available when authentication is needed, enabling immediate verification of client terminal authenticity without compromising network communication safety.
Data Source
AI summary
Provided is a terminal authentication system including a client terminal and a server device. The client terminal transmits first information based on secret information different for each client terminal and a client certificate including a hash value of the secret information which is derived from the secret information, to a server device. The server device receives the first information and the client certificate, derives a hash value from the secret information based on the first information using a unidirectional function, and authenticates the client terminal on the basis of the derived hash value and the hash value of the secret information which is included in the client certificate.


