Wireless User Authentication Device Using Short-Term Symmetric Advertising Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic protocols for portable devices lack effective methods to verify the presence and ownership of users, leading to potential unauthorized access and fraud, as they cannot reliably confirm if the device is under the legitimate owner's control.

Innovation Solution

A digital user authentication system using a wireless digital user authentication device (UAD) that establishes a short-term symmetric advertising (STSA) key with a network application, periodically computes and advertises authentication codes, and employs elliptic-curve Diffie-Hellman or RSA key agreement protocols to ensure secure user presence verification and access authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cryptographic protocols are used for portable devices, then device operation is simplified, but user presence verification security is insufficient

Engineering Contradiction:
Improveuser presence verification securityVSAvoidcryptographic protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cryptographic protocol is segmented into distinct phases: initial authentication phase using asymmetric cryptography, followed by a streamlined advertising phase using symmetric cryptography. This segmentation allows the system to achieve high security for user presence verification while reducing operational complexity during normal advertising cycles.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary asymmetric authentication to establish a shared symmetric key before entering the advertising phase. This preliminary action ensures that subsequent advertising operations can use simpler symmetric cryptography, thereby improving verification security without requiring complex cryptographic operations during normal operation.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If periodic authentication codes are advertised continuously, then user presence verification is improved, but energy consumption increases

Engineering Contradiction:
Improveuser presence verificationVSAvoiddevice energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system implements periodic advertising of authentication codes at defined intervals rather than continuous transmission. This periodic action maintains reliable user presence verification while significantly reducing energy consumption compared to continuous advertising, as the device can enter low-power states between advertising cycles.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system uses short-term symmetric advertising keys with limited validity periods. These temporary keys are discarded and replaced periodically, enabling energy-efficient re-authentication without requiring long-lived cryptographic materials. This approach maintains verification reliability while reducing the energy burden of continuous security maintenance.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Productivity

If short-term symmetric advertising keys are used, then advertising efficiency is improved, but key management complexity increases

Engineering Contradiction:
Improveadvertising efficiencyVSAvoidkey management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system implements self-service key management where the portable device autonomously generates, stores, and rotates its own short-term symmetric advertising keys without requiring external key management infrastructure. This self-service approach improves advertising efficiency by eliminating key management bottlenecks while containing complexity within the individual device rather than the system architecture.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system introduces an intermediary asymmetric key pair as a mediator between long-term security credentials and short-term advertising keys. This intermediary layer simplifies key management by providing a stable root of trust that can securely generate and validate multiple rotating symmetric keys without requiring direct management of each individual advertising key.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If authentication codes are advertised frequently, then fraud prevention is improved, but communication overhead increases

Engineering Contradiction:
Improvefraud preventionVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system changes the parameter of cryptographic key type from asymmetric to symmetric for advertising operations. This parameter change enables more frequent authentication code advertising with reduced message sizes, thereby improving fraud prevention through frequent verification while minimizing communication overhead compared to asymmetric cryptographic operations.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11678186B2Cryptographic process for portable devices, and user presence and/or access authorization system and method employing same
Publication Date: 2023.06.13 NYMI
  • US11678186B2 patent drawing
  • US11678186B2 patent drawing
  • US11678186B2 patent drawing

AI summary

Described are various embodiments of a cryptographic process for portable devices, and user presence and/or access authorization systems and methods employing such protocols. In one embodiment, a digital user authentication system is described to comprise a wireless digital user authentication device (UAD) operable to authenticate the user and wirelessly communicate an authenticated identity thereof; and a network application operatively associated with a wireless access point and operable to authenticate the user presence. Upon the network application authenticating the user presence based, at least in part, on the authenticated identity, the UAD and the network application securely establish a short-term symmetric advertising (STSA) key. During a prescribed advertising lifetime of the STSA, the UAD periodically computes and advertises authentication codes encompassing the STSA key so to securely advertise the authenticated user presence.