Desktop Authentication Module for Secure Two-Factor Enrollment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems often rely on single-factor authentication, which is inadequate for securing sensitive computing resources, particularly during enrollment and PIN unblocking processes, as they require access to the same resources intended to be protected, posing a risk of unauthorized access.

Innovation Solution

A desktop authentication module that employs a smart access card with a card reader interface and an enrollment server for two-factor authentication, preventing access to computing resources until successful completion of the authentication process, thereby enabling secure enrollment and PIN unblocking without granting initial access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If single-factor authentication is used, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of authenticationVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent combines multiple authentication factors (smart card possession and PIN knowledge) into a unified authentication process. The desktop authentication module integrates both factors and submits them together to the authentication server, creating a merged authentication mechanism that provides strong security while maintaining operational simplicity through automated processing.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The desktop authentication module serves as an intermediary between the user and the authentication server. It automatically manages the two-factor authentication process by collecting the smart card and PIN from the user, processing both factors through the module, and submitting them to the server, thereby simplifying the user experience while ensuring strong authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If access to computing resources is granted during enrollment, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveenrollment convenienceVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication verification before granting any access to computing resources during enrollment. The desktop authentication module validates both the smart card and PIN factors, and only after successful authentication does the system proceed to allow enrollment operations, ensuring security is established before resource access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The enrollment process is segmented into distinct phases: authentication verification phase and resource access phase. The desktop authentication module handles the authentication phase separately, and only after successful verification does the system transition to the resource access phase, creating a clear separation between security verification and operational access.

Inventive Principle:
Principle #1Segmentation

3Reliability

If two-factor authentication is implemented, then authentication security is improved, but device complexity is worsened

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The desktop authentication module is designed as a universal component that handles multiple authentication factors (smart card reading, PIN collection, cryptographic verification) within a single integrated system. This multi-functional approach consolidates what could be separate complex systems into one unified module, reducing overall system complexity while maintaining strong two-factor authentication.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If strong authentication is required for enrollment, then security is improved, but productivity is worsened

Engineering Contradiction:
Improveenrollment securityVSAvoidenrollment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The desktop authentication module implements self-service functionality by automatically managing the two-factor authentication process. It autonomously reads the smart card, collects the PIN, performs cryptographic verification, and submits authentication to the server without requiring manual intervention or complex user actions, thereby maintaining fast enrollment speed while ensuring strong security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7536722B1Authentication system for two-factor authentication in enrollment and pin unblock
Publication Date: 2009.05.19 ORACLE AMERICAN INC
  • US7536722B1 patent drawing
  • US7536722B1 patent drawing
  • US7536722B1 patent drawing

AI summary

An authentication system includes a smart access card issued to a user, a client computer, a desktop authentication module configured to prevent a user from accessing resources of the client computer prior to successful completion of a two factor authentication; a card reader interface providing communication between the smart access card and the desktop authentication module; and an enrollment server for enrolling the access card into a server data store. The smart access card has an authentication credential comprising an authentication certificate and a card unique identifier. The enrollment server is in communication with the desktop authentication module via a network connection for receiving the authentication credential from the smart access card and performing two factor authentication for a user, the two factor authentication using the authentication credential prior to the enrolling.