Admin Token Two-Factor Authentication for Security Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing security token systems face security risks due to the reliance on a single-factor authentication process using admin PINs, which can be compromised, and the challenge of securely managing and storing unique admin PINs for each user.
Innovation Solution
A method is introduced that involves providing user-identification data to an admin token, receiving an administrator code, and authenticating the admin token holder to enable administrative operations on user tokens, including unlocking, personalization, and data management, while ensuring two-factor authentication through possession and knowledge verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a one-factor authentication process using admin PIN is used to unlock user tokens, then the ease of operation is improved, but the security is worsened
Solution Approach 1:
The authentication process is segmented into two distinct factors: possession of the admin token and knowledge of the PIN code. This segmentation ensures that both elements are required independently, preventing unauthorized access even if one factor is compromised.
Solution Approach 2:
The admin token serves as an intermediary device that mediates the authentication process. It holds the administrative capabilities and requires both physical possession and PIN verification to execute administrative operations, thereby enhancing security while maintaining operational ease.
2Reliability
If unique admin PINs are assigned to each user to enhance security, then the security is improved, but the device complexity is worsened
Solution Approach 1:
The admin token performs self-service by internally managing the authentication logic and administrative operations. Each token is self-contained with necessary security credentials, eliminating the need for complex external storage and management systems for multiple admin PINs.
Solution Approach 2:
Instead of storing multiple unique admin PINs in a centralized system, the functionality is copied to individual admin tokens. Each token contains the necessary administrative capabilities and security credentials, simplifying the overall system architecture while maintaining security.
Data Source
AI summary
Some demonstrative embodiments of the invention include a method, device and/or system of performing an administrative operation on a user token. The method may include, for example, providing to an admin token user-identification data identifying the user token; receiving from the admin token an administrator code to enable performing the administrative operation; and providing the administrator code to the user token. Other embodiments are described and claimed.


