Visual Cryptographic Key Exchange for Secure Mobile Device Pairing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing techniques for authenticating mobile devices to immobile devices do not establish a trust relationship, leaving them vulnerable to man-in-the-middle and eavesdropping attacks, particularly when using self-signed certificates that omit the trust provided by a trusted third party.

Innovation Solution

A method where the immobile device provides a visual or proximity-based cryptographic key to the mobile device, allowing secure communication by decoding a visual pattern or direct electrical contact, and establishing a secure wireless TCP/IP channel using this key for encrypted data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PKI with trusted third party is used to establish security, then trust relationship is established, but device complexity and administrative overhead increase

Engineering Contradiction:
Improvetrust relationshipVSAvoidadministrative overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the trusted third party (certificate authority) from the authentication process. Instead of relying on external certification, the system uses direct peer-to-peer key exchange where devices authenticate each other through visual or proximity-based cryptographic key sharing, eliminating the need for centralized PKI infrastructure while maintaining security

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system enables devices to perform their own mutual authentication without external assistance. Each device generates and shares cryptographic keys directly with the other device through visual patterns or proximity communication, allowing the devices to self-establish trust relationships without requiring certificate authorities or third-party verification

Inventive Principle:
Principle #25Self-service

2Device complexity

If self-signed certificates are used to reduce cost and administration, then device complexity decreases, but trust relationship is compromised

Engineering Contradiction:
Improveadministrative overheadVSAvoidtrust relationship
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces visual patterns and proximity-based communication as intermediaries in the key exchange process. These intermediaries provide a physical or visual medium that ensures keys are exchanged only between intended parties, preventing spoofing and man-in-the-middle attacks without requiring complex certificate management

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication through visual or proximity-based key exchange before establishing encrypted communication channels. This preliminary action ensures that devices verify each other's identity before any sensitive data transmission, establishing trust upfront without requiring ongoing certificate validation

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If traditional authentication techniques are used, then mobile device to immobile device authentication is achieved, but bidirectional trust is not established

Engineering Contradiction:
Improveauthentication capabilityVSAvoidbidirectional trust
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges authentication and key exchange into a single simultaneous process. Both devices authenticate each other and establish shared cryptographic keys through the same visual or proximity-based interaction, ensuring bidirectional trust is established in one unified action rather than separate one-way authentication steps

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9565173B2Systems and methods for establishing trusted, secure communications from a mobile device to a multi-function device
Publication Date: 2017.02.07 XEROX CORP
  • US9565173B2 patent drawing
  • US9565173B2 patent drawing

AI summary

The present invention generally relates to systems and methods for establishing trusted, secure communications from a mobile device, such as a smart phone, to an immobile device, such as a multi-function device. The disclosed techniques can include the immobile device displaying a pattern that encodes a cryptographic key. The mobile device can obtain an image of the pattern and decode it to obtain the cryptographic key. Because the mobile device obtained the image within its line-of-sight, for example, it can be assured that it communicated with the immobile device, and only the immobile device. The mobile device and the immobile device can use the cryptographic key to secure further communications.