Chained Authentication Tokens Prevent Device Cloning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security protocols for networks face challenges in distinguishing between original and cloned devices, leading to credential theft and misuse, particularly in service-oriented industries, where simpler and less expensive techniques are needed to authenticate devices securely.
Innovation Solution
The advanced chained authentication and authorization system (ACAAS) uses Registration Authorization Tokens (RATs) and Nonce (NONCE) values to verify the authenticity of devices by leveraging secrets derived during the device registration process, ensuring only the original device can authenticate, and includes mechanisms to prevent reply-attacks and credential sharing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complex systems and databases are deployed to identify original vs cloned devices, then device authentication reliability is improved, but system complexity and cost increase
Solution Approach 1:
The patent extracts the essential authentication verification function from complex database systems and identifies it through analysis of authentication traces and credential patterns. By taking out only the critical verification elements (authentication traces, credential patterns, fingerprinting data), the system achieves reliable device identification without requiring complex underlying infrastructure.
Solution Approach 2:
The patent employs disposable authentication traces and temporary fingerprinting data that are generated during authentication exchanges. These short-living objects are discarded after use, eliminating the need for persistent complex databases while maintaining authentication reliability through ephemeral verification mechanisms.
2Ease of operation
If existing authentication protocols are used, then ease of operation is maintained, but security against credential sharing and cloning deteriorates
Solution Approach 1:
The patent applies preliminary anti-action by analyzing authentication traces and credential patterns before actual credential sharing or cloning can occur. The system proactively identifies cloned devices through fingerprinting techniques and authentication trace analysis, preventing harmful factors from taking effect rather than reacting after damage occurs.
Solution Approach 2:
The patent introduces authentication traces and fingerprinting data as intermediary elements between the authentication protocol and the device identification system. These intermediaries enable the system to distinguish between original and cloned devices without modifying the core authentication operation, maintaining ease of use while blocking credential sharing attacks.
Data Source
AI summary
A server device is provided for authenticating client devices on a communication network. The server device includes a transceiver configured for operable communication with at least one client of the communication network, and a processor including a memory configured to store computer-executable instructions. When executed by the processor, the instructions cause the server device to transmit one or more messages of an authentication exchange with a client device, transmit a server Registration Authorization Token (RAT) associated with the server device to the client device, receive from the client device a client RAT associated with the client device, and store the client RAT.


