Device-Bound Authenticator Caller Verification via Signature Chain
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional techniques for managing user identity authentication requests through device-bound authenticators are deficient, particularly in cases where the coupling between authenticating and authenticator applications is loose, making them susceptible to attacks and compromising security.
Innovation Solution
Implementing a framework for authenticator applications or identity providers to establish an authenticity and signature chain of the calling process by identifying a process ID associated with the network connection, obtaining a signature and metadata, and verifying the source's authorization to request user identity authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a loose coupling between authenticating and authenticator applications is used, then ease of operation and adaptability are improved, but security and reliability deteriorate due to susceptibility to attacks
Solution Approach 1:
The patent introduces an intermediary verification mechanism that acts as a mediator between the authenticating application and the authenticator application. This intermediary process validates the caller process using a signature chain before allowing authentication requests to proceed, thereby maintaining security while preserving the loose coupling architecture's operational ease and adaptability.
2Device complexity
If conventional authentication management techniques are used, then device complexity is reduced, but security and reliability deteriorate due to susceptibility to malicious attacks
Solution Approach 1:
The patent implements preliminary action by performing caller process verification through signature chain validation before the actual authentication process begins. This pre-verification step ensures that only authorized processes can initiate authentication requests, thereby enhancing security and reliability without significantly increasing device complexity, as the verification is integrated into the existing authentication flow.
3Reliability
If caller process verification with signature chain is implemented, then security and reliability are improved, but device complexity and processing requirements increase
Solution Approach 1:
The patent merges the caller process verification functionality directly into the existing authentication process. The signature chain validation is combined with the authentication request handling, allowing both functions to be performed within the same process flow. This integration approach enhances security and reliability while minimizing the increase in device complexity, as separate verification infrastructure is not required.
Data Source
AI summary
Methods, systems, and devices for process verification are described. An authenticator application of a device may receive, from an authenticating application of the device, a first request to establish a network connection between the authenticator application and the authenticating application. The first request may identify a port associated with the network connection. The authenticator application may receive a second request from the authenticating application to authenticate an identity of a user. The authenticator application may identify a process used to establish the network connection between the authenticator application and the authenticating application on the port. The authenticator application may obtain a signature and a set of data associated with the signature based on the identified process. The authenticator application may authenticate the identity of the user based on the signature and the associated set of data.


