Authentication System Using Weak Light for Secure Key Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems face challenges in securely sharing secret keys between authentication servers and client devices, particularly due to vulnerabilities in password management and transmission, which can lead to unauthorized access and eavesdropping.

Innovation Solution

An authentication system utilizing an intensity modulated weak light source, storage media, and detection units to generate and verify transmission and reception time information, ensuring secure key sharing through quantum channels and classical channels with pre-shared keys, while resisting attacks like wiretapping and intercept/resend attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a fixed password is used in authentication systems, then ease of operation is improved, but security deteriorates as unauthorized persons can easily infer the password

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic password generation where passwords change frequently based on time and random factors. The authentication server and client device generate passwords using time-varying algorithms and random numbers, ensuring that passwords are different for each authentication session. This resolves the contradiction by making passwords dynamic rather than fixed, maintaining ease of operation through automated generation while significantly improving security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a password generation algorithm as an intermediary that uses time information and random numbers to generate passwords. This intermediary mechanism allows both the authentication server and client device to independently generate the same password without transmitting it, resolving the contradiction by providing a secure method for password generation that balances ease of use with security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If passwords are frequently transmitted via communication lines, then ease of operation is improved, but security deteriorates as unauthorized persons can steal passwords through wiretapping

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent uses a password generation algorithm as an intermediary that enables both parties to independently generate identical passwords using time information and random numbers. This eliminates the need to transmit passwords through communication lines, resolving the contradiction by providing ease of operation through automated password generation while ensuring security by avoiding password transmission entirely.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical system of password transmission with an information-theoretic approach using time-synchronized random number generation. Instead of transmitting passwords through vulnerable communication channels, the system uses time information and random numbers to generate passwords locally at both ends, substituting the transmission mechanism with a generation mechanism that maintains ease of operation while eliminating security vulnerabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If cryptographic communication using quantum mechanical properties is used for password generation, then security is improved, but device complexity increases making it difficult to share secret keys

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses disposable, short-lived random numbers generated from time information and simple algorithms rather than complex quantum mechanical systems. The random numbers are generated locally using inexpensive time-keeping devices and cryptographic algorithms, achieving high security without requiring complex quantum equipment or difficult secret key sharing mechanisms.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent substitutes complex quantum mechanical password generation systems with a simpler information-processing approach using time-synchronized random number generation. By replacing quantum mechanical mechanisms with computational algorithms based on time and randomness, the system achieves comparable or superior security while dramatically reducing device complexity and eliminating the difficulty of secret key sharing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

The system effectively authenticates authorized users by detecting unauthorized access and securely sharing secret keys, significantly reducing the probability of unauthorized use, even under potential attacks, thus enhancing security and user authentication.

Implementation Method 1

cryptographic communication using quantum mechanical properties for generation and distribution of passwords

Methodology Applied
Scientific EffectQuantum mechanical properties:

Implementation Method 2

The detecting unit detects the intensity modulated weak light via a quantum channel

Methodology Applied
Scientific EffectQuantum channel detection:

Data Source

PatentUS10411890B2Authentication system, authentication side device, and security system
Publication Date: 2019.09.10 OKI ELECTRIC INDUSTRY CO LTD
  • US10411890B2 patent drawing
  • US10411890B2 patent drawing
  • US10411890B2 patent drawing

AI summary

The authentication system comprises: the authentication side unit configured to include the intensity modulated weak light source, the first reading unit, the decrypting unit, and the determining unit; and the client side unit configured to include the detecting unit, the second reading unit, and the encrypting unit. The intensity modulated weak light source generates intensity modulated weak light. The first reading unit reads the transmission time information. The detecting unit detects the intensity modulated weak light, and records the detected time in the second storage medium as reception time information. The encrypting unit encrypts all or part of the reception time information and generates encrypted information. The decrypting unit decrypts the encrypted information, and acquires all or part of the reception time information. The determining unit acquires a number of coincidence events and a number of elements of the all or part of the reception time information, generates determination information including information indicating approval when both of the number of coincidence events and the number of elements are within a range of a set value which is set in advance, and generates determination information including information indicating a denial in the other cases.