Admin Token Two-Factor Authentication for Security Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing security token systems face security risks due to the reliance on a single-factor authentication process using admin PINs, which can be compromised, and the challenge of securely managing and storing unique admin PINs for each user.

Innovation Solution

A method is introduced that involves providing user-identification data to an admin token, receiving an administrator code, and authenticating the admin token holder to enable administrative operations on user tokens, including unlocking, personalization, and data management, while ensuring two-factor authentication through possession and knowledge verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a one-factor authentication process using admin PIN is used to unlock user tokens, then the ease of operation is improved, but the security is worsened

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into two distinct factors: possession of the admin token and knowledge of the PIN code. This segmentation ensures that both elements are required independently, preventing unauthorized access even if one factor is compromised.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The admin token serves as an intermediary device that mediates the authentication process. It holds the administrative capabilities and requires both physical possession and PIN verification to execute administrative operations, thereby enhancing security while maintaining operational ease.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If unique admin PINs are assigned to each user to enhance security, then the security is improved, but the device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The admin token performs self-service by internally managing the authentication logic and administrative operations. Each token is self-contained with necessary security credentials, eliminating the need for complex external storage and management systems for multiple admin PINs.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Instead of storing multiple unique admin PINs in a centralized system, the functionality is copied to individual admin tokens. Each token contains the necessary administrative capabilities and security credentials, simplifying the overall system architecture while maintaining security.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8387125B2Device, system and method of performing an administrative operation on a security token
Publication Date: 2013.02.26 K K ATHENA SMARTCARD SOLUTIONS
  • US8387125B2 patent drawing
  • US8387125B2 patent drawing
  • US8387125B2 patent drawing

AI summary

Some demonstrative embodiments of the invention include a method, device and/or system of performing an administrative operation on a user token. The method may include, for example, providing to an admin token user-identification data identifying the user token; receiving from the admin token an administrator code to enable performing the administrative operation; and providing the administrator code to the user token. Other embodiments are described and claimed.