UWB Authentication Using Pre-Shared Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The current FiRa specification for ultra-wide band (UWB) communication requires a time-consuming and complex secure channel establishment process for authentication between terminals, making it difficult to perform authentication quickly, such as within 1 second.

Innovation Solution

A method where an authentication key is pre-shared between terminals, and a session key for UWB ranging is generated using the shared authentication key and a random value, allowing authentication to be performed without establishing a secure channel, thereby simplifying the authentication process and reducing the time required.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure channel is established via the GENERAL AUTHENTICATE command before authentication, then security is improved, but authentication time increases and becomes complicated

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authentication key is pre-shared between terminals before the authentication process begins. This preliminary action eliminates the need for time-consuming secure channel establishment during authentication, as the terminals already possess the necessary cryptographic material to perform authentication directly

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the secure channel establishment step from the authentication process. By separating these functions, the authentication can proceed using pre-shared keys without requiring the complex GENERAL AUTHENTICATE command sequence, thus reducing authentication time while maintaining security through the extracted key-based mechanism

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If a secure channel is established via the GENERAL AUTHENTICATE command before authentication, then security is improved, but the authentication procedure becomes complicated

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the secure channel establishment step from the authentication process. By separating these functions, the authentication can proceed using pre-shared keys without requiring the complex GENERAL AUTHENTICATE command sequence, thus reducing authentication time while maintaining security through the extracted key-based mechanism

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication key is pre-shared between terminals before the authentication process begins. This preliminary action eliminates the need for time-consuming secure channel establishment during authentication, as the terminals already possess the necessary cryptographic material to perform authentication directly

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a secure channel is established for authentication, then security is improved, but power consumption increases

Engineering Contradiction:
Improveauthentication securityVSAvoidpower consumption during authentication
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the secure channel establishment step from the authentication process. By separating these functions, the authentication can proceed using pre-shared keys without requiring the complex GENERAL AUTHENTICATE command sequence, thus reducing authentication time while maintaining security through the extracted key-based mechanism

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication key is pre-shared between terminals before the authentication process begins. This preliminary action eliminates the need for time-consuming secure channel establishment during authentication, as the terminals already possess the necessary cryptographic material to perform authentication directly

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4117230B1Authentication method between terminals having proximity communication function and terminals implementing the same method
Publication Date: 2025.01.29 SAMSUNG SDS CO LTD
  • EP4117230B1 patent drawingFigure 1
  • EP4117230B1 patent drawingFigure 2
  • EP4117230B1 patent drawingFigure 3

AI summary

An authentication method in a secure channel unused mode on a first terminal in which Fine Ranging (FiRa) applet drives according to an embodiment of the present disclosure includes generating a session basic information including a random value, transmitting the generated session basic information to a second terminal, generating session data including a session key from the generated session basic information by using an authentication key pre-shared with the second terminal, and performing ultra-wide band (UWB) ranging with the second terminal by using the generated session data.