Broker Module for Secure Credential Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods, such as username and password paradigms, are vulnerable to attacks like keyloggers and phishing, and deploying additional credential factors can be costly and inefficient, especially when using untrusted or semi-trusted computing environments.

Innovation Solution

A method and system that leverage existing credential tokens and reading equipment by using a broker module in a trusted environment to securely process and transmit sensitive data, generating transformed commands and responses, and creating an audit log for verification, thereby enhancing security and reliability in transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If username and password authentication is used, then authentication is provided, but the system becomes vulnerable to keyloggers and phishing attacks

Engineering Contradiction:
Improveauthentication securityVSAvoidvulnerability to keyloggers and phishing
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a broker module as an intermediary between the application module and the credential. The broker module resides in a trusted environment and handles all sensitive data processing, command transformation, and credential communication. This intermediary architecture prevents direct exposure of sensitive data to untrusted environments, thereby mitigating vulnerabilities to keyloggers and phishing attacks while maintaining authentication functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If additional credential factors are deployed to enhance security, then authentication strength is improved, but the system becomes more costly and complex

Engineering Contradiction:
Improveauthentication strengthVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The broker module is designed to handle multiple types of credential factors (e.g., smart cards, mobile phones, tokens) through a unified architecture. The same broker module can process different credential types by transforming application module commands into appropriate credential-specific commands and vice versa. This multi-functional design enhances authentication strength without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

By centralizing credential processing in the broker module, the system avoids the need for multiple separate authentication systems. The broker module serves as a single point of contact for all credential operations, simplifying the overall system architecture while supporting diverse authentication factors.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If credential processing is done in untrusted environments, then device complexity is reduced, but sensitive data becomes exposed to attacks

Engineering Contradiction:
Improvesystem simplicityVSAvoiddata exposure to attacks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authentication system into two distinct parts: an untrusted application module that initiates authentication requests and a trusted broker module that processes sensitive data. This segmentation allows the system to maintain simplicity in the user-facing application while isolating sensitive data processing in a secure environment, preventing data exposure to attacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The broker module acts as a trusted intermediary that sits between the untrusted application module and the credential. It receives commands from the application module, transforms them into secure credential commands, processes sensitive data, and returns appropriate responses. This intermediary architecture maintains system simplicity from the user perspective while protecting sensitive data from exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If a broker module in a trusted environment is used to process sensitive data, then security is enhanced, but the system complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The broker module is designed as a universal interface that handles multiple authentication scenarios and credential types through a single unified architecture. By implementing a standardized command transformation and data processing framework, the system can enhance data protection across diverse authentication methods without proportionally increasing architectural complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9300665B2Credential authentication methods and systems
Publication Date: 2016.03.29 2859824 ONTARIO LTD
  • US9300665B2 patent drawing
  • US9300665B2 patent drawing
  • US9300665B2 patent drawing

AI summary

Methods and systems are provided for performing and verifying transactions involving authentication with a secure credential, such as a smart card, in an untrusted or semi-trusted environment. An application module, operating in an untrusted or semi-trusted environment can be denied access to sensitive data. The application module can determine a preliminary command to be sent to the credential and transmit the preliminary command to a broker module. The broker module, operating in a trusted environment, can supply sensitive data and transmit the command to the credential. Subsequently, the broker module can extract sensitive data from a response before it is transmitted to the application module. A verification server can audit the transaction to verify that it was carried out properly.