Hardware Authentication Token Isolation for Secure Computing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing devices with integrated authentication tokens face security risks due to potential compromise of the general-purpose processor accessing the authentication token, especially when soft tokens are used, as they may offer little additional security over traditional credentials and can be vulnerable to attacks.
Innovation Solution
Implementing a hardware-integrated authentication token with physical, electrical, or communicative separation from the general-purpose processor, ensuring the processor cannot access the token-generated codes, and using a shared display to render the token interface while maintaining electromagnetic isolation to prevent data access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a hardware-integrated authentication token is implemented with physical separation from the general-purpose processor, then security is improved by preventing processor access to token codes, but device complexity increases due to additional isolation mechanisms
Solution Approach 1:
The authentication token is segmented as a separate hardware module physically isolated from the general-purpose processor. This segmentation ensures that even if the processor is compromised, the token codes remain protected in the isolated authentication module, directly resolving the security versus complexity contradiction by organizing components into secure segments.
Solution Approach 2:
A display interface acts as an intermediary between the isolated authentication token and the user. The display renders token codes without requiring direct processor access to the token module, providing a safe mediation layer that maintains security while enabling code output. This intermediary approach allows secure isolation while still achieving the desired functionality.
2Reliability
If electromagnetic isolation is implemented to prevent processor access to the authentication token, then security is enhanced, but manufacturing complexity increases
Solution Approach 1:
The patent replaces complex mechanical or physical barrier isolation with electromagnetic field isolation techniques. By using electromagnetic shielding and isolated power domains, the solution achieves secure separation without requiring complex mechanical structures, thereby enhancing security while maintaining ease of manufacture through established electromagnetic isolation practices.
3Ease of operation
If a shared display is used to render the token interface, then ease of operation is improved by having a single display, but security risks increase due to potential processor access to the display controller
Solution Approach 1:
The display serves as an intermediary component that receives control signals from both the processor and the isolated authentication token. The token can directly control the display through isolated communication channels, allowing the display to function as a shared output device while maintaining security through the intermediary nature of the display interface that doesn't require processor access to token codes.
Data Source
AI summary
Disclosed are various embodiments for a computing device with an integrated authentication token. The computing device includes first circuitry having a processor and a memory and providing general-purpose computing capability. The computing device also includes second circuitry configured to generate data. The first circuitry is incapable of determining the data due to a separation from the second circuitry, and the first and second circuitry may be in a single enclosure.


