Certificate-Based Client Authentication Without Hardware Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication and security systems for client devices are inadequate in providing customization and configurability, particularly in code signing and feature licensing, and often rely on hardware tokens which are undesirable in some scenarios.

Innovation Solution

An automated client service application that authenticates and authorizes client services using a client certificate with configuration information, eliminating the need for hardware encryption tokens, and allows for flexible management of client services through a code signing server that verifies client certificates and determines authorization based on server configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware encryption tokens are used for authentication, then security is improved, but device complexity and cost increase

Engineering Contradiction:
Improveauthentication securityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces hardware-based authentication mechanisms with software-based certificate validation. Instead of requiring physical hardware tokens or encryption devices, the system uses digital certificates and cryptographic verification through standard software components, eliminating the need for specialized hardware while maintaining security

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The authentication system is designed to work across multiple platforms and devices without requiring device-specific hardware. The certificate-based approach provides universal compatibility across different operating systems and device types, allowing the same authentication mechanism to function universally without hardware modifications

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If traditional authentication systems are used, then security is provided, but customization and configurability are limited

Engineering Contradiction:
ImprovesecurityVSAvoidcustomization capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic configuration of authentication policies and certificate validation rules. Administrators can modify authentication requirements, certificate trust lists, and service access policies without requiring system reconfiguration or hardware changes, allowing the security system to adapt to changing organizational requirements

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication system is divided into independent modular components including certificate validation, service authorization, and policy management. Each module can be independently configured and customized, allowing selective implementation of different authentication methods and policies for different services or user groups

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If certificate-based authentication is implemented, then customization is improved, but processing overhead increases

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidauthentication processing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary validation of certificates during the initial connection establishment phase. Trust relationships and certificate validity are verified before actual service transactions occur, allowing subsequent authentication operations to proceed more efficiently with reduced processing overhead

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11444935B2Certificate-based client authentication and authorization for automated interface
Publication Date: 2022.09.13 ARRIS ENTERPRISES LLC
  • US11444935B2 patent drawing
  • US11444935B2 patent drawing
  • US11444935B2 patent drawing

AI summary

A method and system provide the ability to authenticate client services. A private key and a client certificate are created and delivered to a client. Based on the private key and the certificate, a client account is created for the client on a server. One or more signing or feature licensing configurations are created and authorized on the server for the client account. The client certificate and a request to perform a requested client service are received on the server from a client. The request includes configuration information for the requested client service. The server verifies the client certificate and determines whether the client is authorized to perform the requested client service. The determination is based on the configuration information and the one or more authorized client operations. Upon determining that the client is authorized to perform the requested client service, the request is processed the authorization is sent to the client. Upon a determination that the client is not authorized to perform the requested client service, the requested client service is denied.