Authentication Token Server Verification and Transaction Signing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security technologies for remote access to computer systems and applications, such as Public Key Infrastructure (PKI) and general purpose devices, face challenges including complexity, cost, mobility limitations, and vulnerability to social engineering attacks, especially in environments where digital connections are not feasible and user interfaces are insecure.
Innovation Solution
A low-cost strong authentication token that generates one-time passwords and transaction signatures on a secure device with a trustworthy user interface, authenticates servers before generating security values, and presents transaction data and context information for user review, using optical or alternative input mechanisms and cryptographic methods like symmetric encryption, to ensure secure and convenient remote access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Public Key Infrastructure (PKI) is used to provide security for remote access, then authentication reliability is improved, but device complexity and cost increase
Solution Approach 1:
The patent extracts the essential authentication function from the complex PKI infrastructure and implements it in a standalone hardware token. The token contains a simplified cryptographic module that performs authentication without requiring the full PKI infrastructure, including certificate authorities and complex key management systems. This extraction maintains authentication reliability while eliminating infrastructure complexity.
Solution Approach 2:
The patent employs disposable or easily replaceable hardware tokens instead of investing in long-term PKI infrastructure. Each token is a low-cost device that can be individually manufactured and distributed, eliminating the need for expensive infrastructure setup and maintenance. The tokens are designed to be replaced rather than repaired, reducing overall system complexity.
2Reliability
If PKI smart cards and USB tokens are used, then authentication security is improved, but user mobility and ease of operation deteriorate
Solution Approach 1:
The patent designs the hardware token to be universally compatible with multiple devices and systems. The token can interface with smartphones, computers, and other devices without requiring device-specific configurations or drivers. This universal design maintains strong authentication security while significantly improving user mobility and ease of operation.
Solution Approach 2:
The token incorporates all necessary cryptographic functions and user interface elements within itself, making it self-sufficient. Users can operate the token independently without requiring connection to or configuration by host systems. The token manages its own security credentials and performs authentication operations autonomously, enhancing both security and user convenience.
3Ease of operation
If general purpose devices with software applications are used, then ease of operation is improved, but security reliability deteriorates due to vulnerability to malicious software
Solution Approach 1:
The patent segments the authentication system into two distinct parts: a secure hardware token that stores cryptographic credentials and performs secure operations, and a host device that provides the user interface and application functionality. This segmentation isolates the security-critical functions in the tamper-resistant token, protecting them from malicious software on general-purpose devices while maintaining ease of operation through the host's interface.
Solution Approach 2:
The hardware token acts as an intermediary between the user and the authentication system. Instead of storing credentials directly on the vulnerable host device, the token serves as a secure mediator that receives authentication requests, verifies credentials internally, and returns authentication results. This intermediary role protects the security infrastructure from exposure to malicious software while maintaining user-friendly operation through the host device's interface.
4Ease of operation
If optical interfaces are used for data input, then ease of operation is improved, but manufacturing precision requirements increase
Solution Approach 1:
The patent implements optical interfaces with sufficient precision for the specific authentication application rather than maximum possible precision. The optical reading mechanism is designed to accommodate typical variations in user input and environmental conditions, using error correction and validation algorithms to compensate for minor precision limitations. This approach achieves ease of operation without requiring excessively tight manufacturing tolerances.
Data Source
Figure 1a
Figure 1b
Figure 1c
AI summary
The invention defines a strong authentication token that remedies a vulnerability to a certain type of social engineering attacks, by authenticating the server or messages purporting to come from the server prior to generating a one-time password or transaction signature; and, in the case of the generation of a transaction signature, signing not only transaction values but also transaction context information and, prior to generating said transaction signature, presenting said transaction values and transaction context information to the user for the user to review and approve using trustworthy output and input means. It furthermore offers this authentication and review functionality without sacrificing user convenience or cost efficiency, by judiciously coding the transaction data to be signed, thus reducing the transmission size of information that has to be exchanged over the token's trustworthy interfaces.