Authentication Virtual Machine Isolating Hardware Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication systems in computers are vulnerable to attacks and impersonation due to complex and costly security measures, leading to increased complexity and cost, as well as difficulties in integrating authentication subsystems from different manufacturers, and still face risks from malware, Trojans, and viruses.

Innovation Solution

Implementing an authentication virtual machine that isolates the authentication service in a secure virtual machine within the computing environment, providing exclusive access to necessary subsystems during the authentication process, thereby reducing the need for expensive security protocols in component subsystems and enhancing security by segregating authentication processes from other virtual machines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security capabilities are added to authentication subsystems to prevent attacks and impersonation, then security is improved, but device complexity and cost increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication subsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a secure channel or intermediary mechanism between the authentication subsystem and the operating system/application. This secure channel acts as a mediator that protects communications from attacks while keeping the authentication subsystem itself simple and unchanged. The secure channel handles the complexity of security protocols, allowing the authentication subsystem to remain simple while still providing secure authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security capabilities are added to authentication subsystems to prevent attacks and impersonation, then security is improved, but cost increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication subsystem cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The secure channel serves as an intermediary that provides security functionality without requiring expensive security capabilities in each authentication subsystem. By centralizing security functions in the secure channel layer, the patent avoids duplicating expensive security mechanisms across multiple subsystems, thereby reducing overall cost while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security capabilities are added to authentication subsystems, then security is improved, but interoperability between different manufacturers' subsystems deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication subsystem interoperability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The secure channel acts as a universal intermediary layer between diverse authentication subsystems and the operating system. This layer provides standardized secure communication protocols that work with authentication subsystems from different manufacturers, ensuring interoperability while maintaining security. The secure channel handles manufacturer-specific variations, allowing simple, interoperable authentication subsystems to work together securely.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8806481B2Providing temporary exclusive hardware access to virtual machine while performing user authentication
Publication Date: 2014.08.12 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US8806481B2 patent drawing
  • US8806481B2 patent drawing
  • US8806481B2 patent drawing

AI summary

A computer system includes an authentication service running in a virtual machine. The authentication service uses the hardware components of the computer system in performing a user authentication process and responds to a remote call from another virtual machine by performing the user authentication process and returning a result.