Cloud Peripheral Authentication via Client Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current USB authentication methods are limited to peer-to-peer authentication, which does not support cloud-based authentication of peripheral devices connected to remote client systems, lacking the ability to securely authenticate devices in cloud-managed environments and exposing host platforms to security vulnerabilities.

Innovation Solution

A cloud-based authentication protocol that enables remote authentication of peripheral devices by using a cloud server as an authentication initiator, where the client system performs peer-to-peer authentication with the peripheral device and consolidates authentication information to be sent to the cloud server for verification, adhering to USB-C authentication specifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If peer-to-peer authentication is used, then authentication between connected devices is achieved, but cloud-based authentication capability is lost

Engineering Contradiction:
Improveauthentication mode flexibilityVSAvoidsecurity protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a cloud server as an intermediary that mediates between the client system and peripheral devices. The cloud server receives authentication information from the client system, performs remote authentication, and returns authentication results. This intermediary enables cloud-based authentication while maintaining the existing peer-to-peer authentication flow between client and device, thus achieving both authentication modes without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If peer-to-peer authentication is used, then device connection authentication is achieved, but host platform security vulnerabilities increase

Engineering Contradiction:
Improveauthentication simplicityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the cloud server receives authentication information from the client system, processes it, and returns authentication results. This feedback loop enables continuous security verification without requiring complex local authentication procedures. The cloud server can validate authentication credentials, check device policies, and provide real-time security decisions, thereby maintaining ease of operation while reducing security vulnerabilities through centralized security management.

Inventive Principle:
Principle #23Feedback

3Reliability

If cloud-based authentication is implemented, then security protection is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex authentication logic and security verification functions from the local client system and places them in the cloud server. The client system only needs to collect authentication information from peripheral devices and transmit it to the cloud server, significantly reducing local system complexity. The cloud server handles certificate validation, policy enforcement, and security decisions centrally, thereby improving security protection while minimizing the complexity burden on individual client devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3930282B1System, apparatus and method for remotely authenticating peripheral devices
Publication Date: 2023.04.12 INTEL CORP
  • EP3930282B1 patent drawingFigure 1
  • EP3930282B1 patent drawingFigure 2
  • EP3930282B1 patent drawingFigure 3

AI summary

In one embodiment, a method comprises: receiving, in a client system, an authentication request from a cloud server remotely coupled to the client system, the authentication request for authentication of a device coupled to the client system; in response to the authentication request, performing an authentication protocol with the device via the client system, including obtaining device authentication information of the device; placing at least a portion of the device authentication information and authentication information of the client system in a protocol packet, and sending the protocol packet to the cloud server; and in response to a challenge request from the cloud server, sending to the cloud server a challenge response signed with a first certificate of the client system and a second certificate of the device, to cause the cloud server to authenticate the device. Other embodiments are described and claimed.