Wireless User Authentication Device Using Short-Term Symmetric Advertising Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic protocols for portable devices lack effective methods to verify the presence and ownership of users, leading to potential unauthorized access and fraud, as they cannot reliably confirm if the device is under the legitimate owner's control.
Innovation Solution
A digital user authentication system using a wireless digital user authentication device (UAD) that establishes a short-term symmetric advertising (STSA) key with a network application, periodically computes and advertises authentication codes, and employs elliptic-curve Diffie-Hellman or RSA key agreement protocols to ensure secure user presence verification and access authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional cryptographic protocols are used for portable devices, then device operation is simplified, but user presence verification security is insufficient
Solution Approach 1:
The cryptographic protocol is segmented into distinct phases: initial authentication phase using asymmetric cryptography, followed by a streamlined advertising phase using symmetric cryptography. This segmentation allows the system to achieve high security for user presence verification while reducing operational complexity during normal advertising cycles.
Solution Approach 2:
The system performs preliminary asymmetric authentication to establish a shared symmetric key before entering the advertising phase. This preliminary action ensures that subsequent advertising operations can use simpler symmetric cryptography, thereby improving verification security without requiring complex cryptographic operations during normal operation.
2Reliability
If periodic authentication codes are advertised continuously, then user presence verification is improved, but energy consumption increases
Solution Approach 1:
The system implements periodic advertising of authentication codes at defined intervals rather than continuous transmission. This periodic action maintains reliable user presence verification while significantly reducing energy consumption compared to continuous advertising, as the device can enter low-power states between advertising cycles.
Solution Approach 2:
The system uses short-term symmetric advertising keys with limited validity periods. These temporary keys are discarded and replaced periodically, enabling energy-efficient re-authentication without requiring long-lived cryptographic materials. This approach maintains verification reliability while reducing the energy burden of continuous security maintenance.
3Productivity
If short-term symmetric advertising keys are used, then advertising efficiency is improved, but key management complexity increases
Solution Approach 1:
The system implements self-service key management where the portable device autonomously generates, stores, and rotates its own short-term symmetric advertising keys without requiring external key management infrastructure. This self-service approach improves advertising efficiency by eliminating key management bottlenecks while containing complexity within the individual device rather than the system architecture.
Solution Approach 2:
The system introduces an intermediary asymmetric key pair as a mediator between long-term security credentials and short-term advertising keys. This intermediary layer simplifies key management by providing a stable root of trust that can securely generate and validate multiple rotating symmetric keys without requiring direct management of each individual advertising key.
4Reliability
If authentication codes are advertised frequently, then fraud prevention is improved, but communication overhead increases
Solution Approach 1:
The system changes the parameter of cryptographic key type from asymmetric to symmetric for advertising operations. This parameter change enables more frequent authentication code advertising with reduced message sizes, thereby improving fraud prevention through frequent verification while minimizing communication overhead compared to asymmetric cryptographic operations.
Data Source
AI summary
Described are various embodiments of a cryptographic process for portable devices, and user presence and/or access authorization systems and methods employing such protocols. In one embodiment, a digital user authentication system is described to comprise a wireless digital user authentication device (UAD) operable to authenticate the user and wirelessly communicate an authenticated identity thereof; and a network application operatively associated with a wireless access point and operable to authenticate the user presence. Upon the network application authenticating the user presence based, at least in part, on the authenticated identity, the UAD and the network application securely establish a short-term symmetric advertising (STSA) key. During a prescribed advertising lifetime of the STSA, the UAD periodically computes and advertises authentication codes encompassing the STSA key so to securely advertise the authenticated user presence.


