Physical Access Token Authentication Using Counterpart Records
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing physical authentication tokens are vulnerable to interception and manipulation in cyberattacks, allowing unauthorized access and data breaches, particularly in sensitive environments like medical networks, where secure authentication without transmitting sensitive data is crucial.
Innovation Solution
A system where physical access tokens and remote servers store counterpart records, generating authentication data independently using deterministic functions, ensuring secure verification without data transmission, and updating records in sync to prevent interception.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical access tokens transmit authentication data to remote servers, then authentication can be performed, but sensitive data may be intercepted by bad actors during transmission
Solution Approach 1:
The patent extracts only the necessary authentication data (hash values) from the authentication process, rather than transmitting full sensitive information. The system transmits minimal data elements that can verify authenticity without exposing underlying sensitive information that could be intercepted and misused.
Solution Approach 2:
The patent introduces hash functions as intermediary elements between the physical access token and remote server. These hash functions transform sensitive authentication data into non-sensitive hash values that serve as mediators, allowing verification without direct exposure of the original sensitive information during transmission.
2Reliability
If physical access tokens store sensitive information locally, then authentication can be performed without transmission, but the token becomes a high-value target for physical attacks
Solution Approach 1:
The patent extracts only the essential authentication capability from the physical token, storing only hash values and minimal authentication data locally rather than complete sensitive information. This extraction reduces the value of the token as a target for physical attacks while maintaining authentication functionality.
Solution Approach 2:
The patent transforms sensitive authentication parameters into non-sensitive hash value parameters. By changing the form of stored data from readable sensitive information to cryptographic hash values, the system maintains authentication capability while significantly reducing vulnerability to physical attacks and unauthorized access.
3Reliability
If authentication data is transmitted frequently for verification, then security can be enhanced, but the system becomes more vulnerable to interception attacks
Solution Approach 1:
The patent employs disposable, single-use authentication tokens that generate unique hash values for each authentication attempt. These short-lived authentication credentials are used once and then discarded, preventing bad actors from benefiting from intercepted data in future attacks, as each token becomes invalid after use.
Solution Approach 2:
The patent implements periodic reauthentication requirements where users must periodically present their physical tokens for verification. This periodic action ensures that even if authentication data were intercepted, it would expire or become invalid by the time of the next required authentication, limiting the window of opportunity for attackers.
Data Source
AI summary
In certain embodiments, a physical network access token at a network access terminal may be authenticated for modification of records at a remote server system. In some embodiments, a set of records and counterpart records having the same record identifiers and resource amounts may be stored independently on a physical token or user device and the remote server system. When a connection is established between an access terminal and the physical token (e.g., for authenticating a modification of record(s)), the access terminal may transmit input data to the token, which may use the input data with the records stored on the token to generate authentication data, which may be used by the remote server to authenticate a network action requested via the token.


