Auxiliary Channel Messaging in Stored-Code Authentication Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional stored-passcode authentication tokens lack the ability to support communication via side channels or auxiliary channels, which are essential for security functions like drifting keys and silent alarms.
Innovation Solution
Implementing an auxiliary channel embedded in passcodes to enable messaging functionality between cryptographic devices, allowing secure communication by selecting and releasing specific passcodes based on message content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If stored-passcode authentication tokens are used to reduce computational resources, then device complexity and energy consumption are reduced, but the ability to support auxiliary channel communication is lost
Solution Approach 1:
The patent segments the passcode generation system into multiple independent sets of passcodes, each set associated with different possible messages. This allows the device to select and transmit specific messages through auxiliary channels by choosing which passcode set to release, thereby enabling communication functionality without requiring complex real-time computation.
Solution Approach 2:
The patent precomputes and stores multiple sets of passcodes in the authentication token before runtime. This preliminary action enables the device to support auxiliary channel communication by having message-encoded passcode sets readily available for selection and release, eliminating the need for complex real-time computation during actual communication.
2Adaptability or versatility
If multiple sets of passcodes are precomputed and stored to enable messaging, then auxiliary channel communication is enabled, but memory resources are increased
Solution Approach 1:
The passcode space is segmented into multiple distinct sets, where each set corresponds to a specific message or message type. This segmentation allows the system to store passcodes in an organized manner, enabling selective release of specific message sets without requiring the storage of all possible passcodes simultaneously, thus optimizing memory utilization.
3Adaptability or versatility
If passcodes are selected based on message content for transmission, then secure messaging is achieved, but passcode security may be degraded
Solution Approach 1:
The patent applies local quality by making different parts of the passcode system serve different functions. Specific passcode sets are designated for specific message types, and the selection process is designed to minimize information leakage. The local structure of each passcode set maintains security properties while enabling targeted message transmission through auxiliary channels.
Data Source
AI summary
A first cryptographic device determines multiple sets of passcodes for possible release in association with a corresponding one of a plurality of epochs, and transmits a message to a second cryptographic device over an auxiliary channel embedded in one or more passcodes released by the first cryptographic device to the second cryptographic device. For example, the first cryptographic device can determine multiple sets of passcodes by precomputing and storing the multiple sets of passcodes, or by generating one or more data sets from which the multiple sets of passcodes can be computed. The first cryptographic device transmits the message over the auxiliary channel by selecting a particular one of the multiple sets of passcodes based on content of the message and releasing a passcode from the selected set. The first cryptographic device may comprise an authentication token and the second cryptographic device may comprise an authentication server.


