Hardware Authentication Token Isolation for Secure Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing devices with integrated authentication tokens face security risks due to potential compromise of the general-purpose processor accessing the authentication token, especially when soft tokens are used, as they may offer little additional security over traditional credentials and can be vulnerable to attacks.

Innovation Solution

Implementing a hardware-integrated authentication token with physical, electrical, or communicative separation from the general-purpose processor, ensuring the processor cannot access the token-generated codes, and using a shared display to render the token interface while maintaining electromagnetic isolation to prevent data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a hardware-integrated authentication token is implemented with physical separation from the general-purpose processor, then security is improved by preventing processor access to token codes, but device complexity increases due to additional isolation mechanisms

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication token is segmented as a separate hardware module physically isolated from the general-purpose processor. This segmentation ensures that even if the processor is compromised, the token codes remain protected in the isolated authentication module, directly resolving the security versus complexity contradiction by organizing components into secure segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A display interface acts as an intermediary between the isolated authentication token and the user. The display renders token codes without requiring direct processor access to the token module, providing a safe mediation layer that maintains security while enabling code output. This intermediary approach allows secure isolation while still achieving the desired functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If electromagnetic isolation is implemented to prevent processor access to the authentication token, then security is enhanced, but manufacturing complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidmanufacturing complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent replaces complex mechanical or physical barrier isolation with electromagnetic field isolation techniques. By using electromagnetic shielding and isolated power domains, the solution achieves secure separation without requiring complex mechanical structures, thereby enhancing security while maintaining ease of manufacture through established electromagnetic isolation practices.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If a shared display is used to render the token interface, then ease of operation is improved by having a single display, but security risks increase due to potential processor access to the display controller

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The display serves as an intermediary component that receives control signals from both the processor and the isolated authentication token. The token can directly control the display through isolated communication channels, allowing the display to function as a shared output device while maintaining security through the intermediary nature of the display interface that doesn't require processor access to token codes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10609021B2Computing device with integrated authentication token
Publication Date: 2020.03.31 AMAZON TECH INC
  • US10609021B2 patent drawing
  • US10609021B2 patent drawing
  • US10609021B2 patent drawing

AI summary

Disclosed are various embodiments for a computing device with an integrated authentication token. The computing device includes first circuitry having a processor and a memory and providing general-purpose computing capability. The computing device also includes second circuitry configured to generate data. The first circuitry is incapable of determining the data due to a separation from the second circuitry, and the first and second circuitry may be in a single enclosure.