Audio Jack Authentication Token User Actuated Secret Release

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication tokens are vulnerable to 'over the shoulder' attacks, differential power analysis, and malware access, with limitations in form factor and compatibility, leading to compromised security and restricted applicability.

Innovation Solution

A user-actuated release of a secret through an audio jack, where a small attachable device with an audio jack operates as a source of a secret, releasing it only upon user activation, providing non-volatile storage and improved security by minimizing secret exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the authentication token constantly generates and outputs OTPs on a display, then the authentication process is streamlined and automatic, but the device becomes vulnerable to over the shoulder attacks and differential power analysis

Engineering Contradiction:
Improveauthentication speedVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the secret (seed) from the display output, releasing it only through an audio jack upon user actuation. This separates the secret generation function from the display function, allowing automatic OTP generation while protecting the seed from visual capture and power analysis attacks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of continuous secret exposure, the patent implements periodic, user-triggered secret release through the audio jack. The secret is released only when the user presses a button, creating discrete exposure events rather than continuous exposure, which mitigates both visual and power analysis attacks.

Inventive Principle:
Principle #19Periodic action

2Reliability

If the authentication token stores the secret in local memory for non-volatile storage, then the secret is protected from device loss or theft, but the device must interface with various device types requiring different connectivity options

Engineering Contradiction:
Improvesecret protectionVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent makes the audio jack universal by implementing it in both the authentication token and various external devices (smartphones, computers, POS terminals, ATMs). This single interface type can accommodate multiple device categories, achieving versatility without requiring multiple specialized connectors.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The audio jack serves as an intermediary interface between the authentication token and diverse external devices. Rather than implementing multiple specialized connectors, the patent uses this common audio interface as a mediator that can connect to various device types through appropriate adapters or native support.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If the authentication token uses wireless access for communication, then the device form factor is reduced and connectivity is improved, but the security could be compromised via over-the-air protocol attacks

Engineering Contradiction:
Improveconnectivity convenienceVSAvoidwireless security vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the secret transmission from wireless communication and redirects it through the wired audio jack interface. This removes the secret exposure from the vulnerable wireless domain while maintaining the convenience of modern device connectivity through the audio jack.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9692751B1User actuated release of a secret through an audio jack to authenticate the user
Publication Date: 2017.06.27 EMC IP HLDG CO LLC
  • US9692751B1 patent drawing
  • US9692751B1 patent drawing
  • US9692751B1 patent drawing

AI summary

A technique provides a secret to authenticate a user. The technique involves storing, by processing circuitry, an initial secret in local memory. The technique further involves receiving, by the processing circuitry, a release command after the initial secret is stored in the local memory. The technique further involves, in response to the release command and based on the initial secret, outputting a released secret through an audio jack which is coupled to the processing circuitry. With such a technique, the secret is only exposed in response to user actuation thus providing improved security against an attacker vis-à-vis a conventional authentication token which constantly generates and outputs a series of one-time use passcodes (OTPs) on a display based on a seed stored in memory.