Authentication Server Shared Secret Key Synchronization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security measures for authentication devices in electronic communication lack user-friendly solutions for administration and protection of multiple devices, especially when one device malfunctions or is lost/stolen, and existing methods increase user burden and costs.
Innovation Solution
A method for mapping multiple authentication devices to a user account using an authentication server, ensuring secure communication channels for data transfer between devices, with a shared secret for encryption and automatic synchronization of information across all devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple authentication devices are used with independent protection measures, then security against abuse is improved, but user burden and complexity increase
Solution Approach 1:
The patent merges the protection mechanisms across multiple authentication devices by introducing a shared secret key that is synchronized to all devices. Instead of each device having independent protection measures, the system combines them into a unified security framework where the same secret key protects all authentication devices, thereby reducing user burden while maintaining security.
Solution Approach 2:
The shared secret key serves multiple functions across different authentication devices. It is used for authentication purposes on all devices, enabling a single security mechanism to perform multiple protection functions simultaneously. This universal approach eliminates the need for users to manage separate protection measures for each device.
2Reliability
If multiple authentication devices are used, then availability and backup options are improved, but data synchronization and security management become more difficult
Solution Approach 1:
The system implements automatic feedback mechanisms where changes to the shared secret key or authentication data on one device are automatically reflected on all other devices. The authentication server monitors and synchronizes the secret key across all devices, providing continuous feedback that maintains consistency without requiring manual intervention from users.
Solution Approach 2:
The authentication system performs self-service synchronization automatically. When a device is added or when data changes occur, the system autonomously synchronizes the shared secret key and relevant data to all other devices through the authentication server, eliminating the need for users to manually manage synchronization between devices.
3Reliability
If independent protection measures are implemented for each authentication device, then security is improved, but costs and user convenience deteriorate
Solution Approach 1:
The patent combines independent protection measures into a unified system by using a single shared secret key across all authentication devices. This merging approach maintains security effectiveness while significantly improving user convenience, as users no longer need to manage separate protection mechanisms for each device.
Solution Approach 2:
The shared secret key is copied to all authentication devices through the authentication server. Instead of each device having unique protection measures, the system creates copies of the same security mechanism across all devices, ensuring consistent security while simplifying user interaction and management.
Data Source
AI summary
The invention provides a method for mapping at least two authentication devices to a user account using an authentication server, where each authentication device connects to the authentication server using a secured communication channel; their mapping to the user account is recorded on the authentication server, and, when a transfer of data between the authentication devices mapped to the user account occurs, the data is passed over from the first authentication device to the authentication server using a secured communication channel and from the authentication server to another authentication device mapped to the account of said user using a secured communication channel, where the aforesaid secured communication channel is created by the second authentication device. This procedure allows the use of a single personal local authentication factor for multiple authentication devices and increases the security of authentication of devices with authentication servers.


