Composite Authenticator Segmentation for Identity Theft Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure user authentication systems over networks face challenges in protecting against identity theft, phishing, and malware attacks, particularly in ensuring that authentication keys are secure and user verification is not bypassed by malicious software.

Innovation Solution

Implementing composite authenticators with independent components, each having its own protection logic and cryptographic key management, including a user verification component, display component, and authenticator kernel, which securely manage attestation and authentication keys, and leverage hardware and software protection mechanisms to ensure secure communication and user authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing authentication systems are used, then user authentication can be performed, but security against identity theft and phishing attacks is insufficient

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is divided into separate components: a first authenticator containing a first cryptographic key, a second authenticator containing a second cryptographic key, and a relying party that verifies both. This segmentation isolates security risks to individual components while maintaining overall system security, preventing identity theft and phishing attacks through multi-factor authentication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a composite authentication system that combines multiple authenticators (first authenticator with first key, second authenticator with second key) into a unified authentication process. This composite structure provides enhanced security against identity theft and phishing attacks by requiring verification from multiple independent authentication sources.

Inventive Principle:
Principle #40Composite materials

2Ease of operation

If authentication keys are managed centrally, then key management is simplified, but security against malware attacks is reduced

Engineering Contradiction:
Improvekey managementVSAvoidprotection against malware
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Cryptographic key management is segmented across multiple independent authenticators. The first authenticator manages the first cryptographic key while the second authenticator manages the second cryptographic key. This distribution prevents malware from compromising all keys through a single point of failure, while each authenticator maintains independent security controls.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each authenticator implements local security measures tailored to its specific cryptographic key. The first authenticator provides protection for the first key while the second authenticator provides protection for the second key, allowing customized security approaches for different key types and reducing the impact of localized malware attacks.

Inventive Principle:
Principle #3Local quality

3Reliability

If multiple authenticators are used, then security is enhanced, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidnumber of components
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The relying party is designed to universally handle authentication from multiple types of authenticators. It can verify both the first authenticator with the first cryptographic key and the second authenticator with the second cryptographic key through a unified verification process, reducing the operational complexity despite using multiple authenticators.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines multiple authentication verification processes into a single unified authentication flow. The relying party merges the verification of the first authenticator and the second authenticator into one coordinated process, simplifying the user experience while maintaining enhanced security through multiple authentication factors.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10798087B2Apparatus and method for implementing composite authenticators
Publication Date: 2020.10.06 NOK NOK LABS INC
  • US10798087B2 patent drawing
  • US10798087B2 patent drawing
  • US10798087B2 patent drawing

AI summary

A system, apparatus, method, and machine readable medium are described for implementing a composite authenticator. For example, an apparatus in accordance with one embodiment comprises: an authenticator for authenticating a user of the apparatus with a relying party, the authenticator comprising a plurality of authentication components; and component authentication logic to attest to the model and/or integrity of at least one authentication component to one or more of the other authentication components prior to allowing the authentication components to form the authenticator.