Cloud Peripheral Authentication via Client Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current USB authentication methods are limited to peer-to-peer authentication, which does not support cloud-based authentication of peripheral devices connected to remote client systems, lacking the ability to securely authenticate devices in cloud-managed environments and exposing host platforms to security vulnerabilities.
Innovation Solution
A cloud-based authentication protocol that enables remote authentication of peripheral devices by using a cloud server as an authentication initiator, where the client system performs peer-to-peer authentication with the peripheral device and consolidates authentication information to be sent to the cloud server for verification, adhering to USB-C authentication specifications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If peer-to-peer authentication is used, then authentication between connected devices is achieved, but cloud-based authentication capability is lost
Solution Approach 1:
The patent introduces a cloud server as an intermediary that mediates between the client system and peripheral devices. The cloud server receives authentication information from the client system, performs remote authentication, and returns authentication results. This intermediary enables cloud-based authentication while maintaining the existing peer-to-peer authentication flow between client and device, thus achieving both authentication modes without compromising security.
2Ease of operation
If peer-to-peer authentication is used, then device connection authentication is achieved, but host platform security vulnerabilities increase
Solution Approach 1:
The patent implements a feedback mechanism where the cloud server receives authentication information from the client system, processes it, and returns authentication results. This feedback loop enables continuous security verification without requiring complex local authentication procedures. The cloud server can validate authentication credentials, check device policies, and provide real-time security decisions, thereby maintaining ease of operation while reducing security vulnerabilities through centralized security management.
3Reliability
If cloud-based authentication is implemented, then security protection is improved, but system complexity increases
Solution Approach 1:
The patent extracts the complex authentication logic and security verification functions from the local client system and places them in the cloud server. The client system only needs to collect authentication information from peripheral devices and transmit it to the cloud server, significantly reducing local system complexity. The cloud server handles certificate validation, policy enforcement, and security decisions centrally, thereby improving security protection while minimizing the complexity burden on individual client devices.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
In one embodiment, a method comprises: receiving, in a client system, an authentication request from a cloud server remotely coupled to the client system, the authentication request for authentication of a device coupled to the client system; in response to the authentication request, performing an authentication protocol with the device via the client system, including obtaining device authentication information of the device; placing at least a portion of the device authentication information and authentication information of the client system in a protocol packet, and sending the protocol packet to the cloud server; and in response to a challenge request from the cloud server, sending to the cloud server a challenge response signed with a first certificate of the client system and a second certificate of the device, to cause the cloud server to authenticate the device. Other embodiments are described and claimed.