Portable Terminal Mutual Authentication via Seed-Based Certificate

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication protocols for secure communication between portable terminals are inadequate as they rely on an authentication center or secure server, making them unsuitable for direct authentication between devices.

Innovation Solution

A method and apparatus for portable terminals to authenticate each other using an authentication certificate generated from seeds and public keys, transmitted through an authentication channel, enabling secure communication without the need for an authentication center or secure server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication protocols are used, then high security is achieved, but dependency on authentication center and authentication server increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication center and authentication server from the authentication process, enabling portable terminals to perform mutual authentication independently. The authentication function is taken out from external infrastructure and embedded directly into the terminals through public key cryptography and challenge-response protocols.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Portable terminals are enabled to authenticate each other autonomously without external assistance. Each terminal generates its own public-private key pairs, creates authentication information locally, and performs verification independently, making the system self-sufficient.

Inventive Principle:
Principle #25Self-service

2Reliability

If authentication center and authentication server are used, then secure communication is established, but system complexity and infrastructure requirements increase

Engineering Contradiction:
Improvesecure communicationVSAvoidsystem infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent removes the authentication center and authentication server from the system architecture, replacing centralized authentication with decentralized peer-to-peer authentication between portable terminals.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Each portable terminal is designed to perform multiple functions including key generation, authentication information creation, and verification, eliminating the need for specialized authentication infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If mutual authentication between portable terminals is implemented, then secure direct communication is achieved, but authentication protocol complexity increases

Engineering Contradiction:
Improvedirect authenticationVSAvoidauthentication protocol
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication protocol is segmented into distinct phases: key generation phase, authentication information creation phase, and verification phase. This segmentation simplifies the overall complexity by breaking down the authentication process into manageable, sequential steps.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Public-private key pairs are generated in advance before the actual authentication takes place. This preliminary action prepares the terminals for authentication without requiring complex real-time computations during the authentication exchange.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8874919B2Apparatus and method of a portable terminal authenticating another portable terminal
Publication Date: 2014.10.28 SAMSUNG ELECTRONICS CO LTD
  • US8874919B2 patent drawing
  • US8874919B2 patent drawing
  • US8874919B2 patent drawing

AI summary

Provided is an apparatus and method of a portable terminal authenticating another portable terminal. The portable terminal may receive a seed generated by the other portable terminal, issue an authentication certificate generated using the seed to the other portable terminal, authenticate the other portable terminal based on the authentication certificate, and provide a secure communication.