Auxiliary Channel Messaging in Stored-Code Authentication Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional stored-passcode authentication tokens lack the ability to support communication via side channels or auxiliary channels, which are essential for security functions like drifting keys and silent alarms.

Innovation Solution

Implementing an auxiliary channel embedded in passcodes to enable messaging functionality between cryptographic devices, allowing secure communication by selecting and releasing specific passcodes based on message content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If stored-passcode authentication tokens are used to reduce computational resources, then device complexity and energy consumption are reduced, but the ability to support auxiliary channel communication is lost

Engineering Contradiction:
Improvecomputational resourcesVSAvoidauxiliary channel communication capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the passcode generation system into multiple independent sets of passcodes, each set associated with different possible messages. This allows the device to select and transmit specific messages through auxiliary channels by choosing which passcode set to release, thereby enabling communication functionality without requiring complex real-time computation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent precomputes and stores multiple sets of passcodes in the authentication token before runtime. This preliminary action enables the device to support auxiliary channel communication by having message-encoded passcode sets readily available for selection and release, eliminating the need for complex real-time computation during actual communication.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If multiple sets of passcodes are precomputed and stored to enable messaging, then auxiliary channel communication is enabled, but memory resources are increased

Engineering Contradiction:
Improvemessaging functionalityVSAvoidmemory resources
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The passcode space is segmented into multiple distinct sets, where each set corresponds to a specific message or message type. This segmentation allows the system to store passcodes in an organized manner, enabling selective release of specific message sets without requiring the storage of all possible passcodes simultaneously, thus optimizing memory utilization.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If passcodes are selected based on message content for transmission, then secure messaging is achieved, but passcode security may be degraded

Engineering Contradiction:
Improvemessage transmission capabilityVSAvoidpasscode security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by making different parts of the passcode system serve different functions. Specific passcode sets are designated for specific message types, and the selection process is designed to minimize information leakage. The local structure of each passcode set maintains security properties while enabling targeted message transmission through auxiliary channels.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10367642B1Cryptographic device configured to transmit messages over an auxiliary channel embedded in passcodes
Publication Date: 2019.07.30 RSA SECURITY USA LLC
  • US10367642B1 patent drawing
  • US10367642B1 patent drawing
  • US10367642B1 patent drawing

AI summary

A first cryptographic device determines multiple sets of passcodes for possible release in association with a corresponding one of a plurality of epochs, and transmits a message to a second cryptographic device over an auxiliary channel embedded in one or more passcodes released by the first cryptographic device to the second cryptographic device. For example, the first cryptographic device can determine multiple sets of passcodes by precomputing and storing the multiple sets of passcodes, or by generating one or more data sets from which the multiple sets of passcodes can be computed. The first cryptographic device transmits the message over the auxiliary channel by selecting a particular one of the multiple sets of passcodes based on content of the message and releasing a passcode from the selected set. The first cryptographic device may comprise an authentication token and the second cryptographic device may comprise an authentication server.