Embedded Tokencode Authentication Server for SOHO Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional home office settings rely on insecure password-based security methods, while large enterprise settings use costly OTP authentication systems, making both approaches impractical for small office/home office environments due to expense and complexity.

Innovation Solution

Implementing a tokencode authentication server embedded within a point of access, such as a networked device that operates as both a NAS or firewall, to control access to resources, eliminating the need for dedicated authentication servers and providing a cost-effective, secure solution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If password-based security is used in home office settings, then ease of operation is improved, but security reliability deteriorates due to weak passwords being easily guessable and permanently compromised

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces permanent passwords with one-time use tokencodes that are valid only for a single authentication attempt. Each tokencode is generated by an authentication token device and expires after use, eliminating the permanent compromise risk associated with passwords while maintaining ease of use through automated generation and validation

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Reliability

If dedicated authentication servers are deployed, then security reliability is improved, but device complexity and implementation cost increase significantly

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication server functionality with existing access point hardware. The access point device integrates both network access control and tokencode authentication operations, eliminating the need for separate dedicated authentication servers. This consolidation reduces implementation complexity while maintaining enterprise-level security reliability

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The access point device is designed to perform multiple functions: providing network access control and simultaneously serving as an authentication server for tokencode validation. This multi-functionality eliminates the need for specialized authentication infrastructure, reducing complexity while maintaining security

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If large enterprise OTP authentication systems are implemented, then security reliability is improved, but implementation cost and complexity increase making it impractical for small offices

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential authentication functionality from complex enterprise OTP systems and implements it within the access point device. By removing unnecessary infrastructure components and implementing only the core tokencode validation function, the system achieves enterprise security reliability at a fraction of the complexity and cost

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9306943B1Access point—authentication server combination
Publication Date: 2016.04.05 RSA SECURITY USA LLC
  • US9306943B1 patent drawing
  • US9306943B1 patent drawing
  • US9306943B1 patent drawing

AI summary

A technique controls access to a protected resource. The technique involves providing a tokencode prompt to a user. The tokencode prompt requests a tokencode from an electronic token in possession of the user. The technique further involves receiving, in response to the tokencode prompt, a current tokencode from the electronic token in possession of the user. The technique further involves performing, by a SOHO device having an embedded tokencode authentication server, an authentication operation based on the current tokencode. A result of the authentication operation (i) permits the user to access the protected resource when the authentication operation determines that the user is legitimate and (ii) denies the user access to the protected resource when the authentication operation determines that the user is not legitimate. For example, the SOHO device may be a NAS device or a firewall device which with tokencode authentication capabilities.