On-demand Epoch Control for Cryptographic Authentication Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication systems, including hardware and software tokens, lack effective epoch control mechanisms, making them vulnerable to breaches and advanced persistent threats, especially in scenarios where breaches go undetected or are slow to be addressed.

Innovation Solution

Implementing on-demand proactivation techniques that allow cryptographic devices to adjust epochs responsive to control signals, enabling premature termination of current epochs and advancement to subsequent ones, with refreshed secret information used for authentication across distributed servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication systems use fixed epoch intervals, then system operation is simple, but security resilience against undetected breaches is insufficient

Engineering Contradiction:
Improvesecurity resilienceVSAvoidepoch control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms the static, fixed epoch interval system into a dynamic one where epoch transitions can be triggered on-demand by control signals. This allows the system to adapt epoch timing based on security conditions, enabling premature epoch termination when breaches are detected while maintaining simple fixed intervals during normal operation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where authentication servers monitor for breach conditions and send control signals back to cryptographic devices when epoch advancement is required. This feedback loop enables the system to respond to security threats by adjusting epoch timing based on real-time security assessments.

Inventive Principle:
Principle #23Feedback

2Speed

If cryptographic devices advance epochs on-demand, then response to detected breaches is rapid, but synchronization complexity increases

Engineering Contradiction:
Improvebreach response speedVSAvoidsynchronization mechanism
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The system prepares for potential breach scenarios by pre-establishing control signal protocols and epoch transition mechanisms. When a breach is detected, the system can immediately execute pre-planned epoch advancement without needing to negotiate or coordinate complex synchronization in real-time, thus maintaining rapid response while managing complexity through advance preparation.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If fixed epoch intervals are used, then system operation is simple, but vulnerability to advanced persistent threats increases

Engineering Contradiction:
Improvethreat vulnerabilityVSAvoidsystem operation
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent extracts the epoch transition trigger mechanism from the fixed timing system, allowing epoch advancement to be decoupled from regular intervals. This separation enables the system to maintain simple fixed scheduling for normal operation while extracting the ability to respond to threats through external control signals, thus reducing threat vulnerability without significantly complicating routine operation.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8699715B1On-demand proactive epoch control for cryptographic devices
Publication Date: 2014.04.15 EMC IP HLDG CO LLC
  • US8699715B1 patent drawing
  • US8699715B1 patent drawing
  • US8699715B1 patent drawing

AI summary

A first cryptographic device is configured to store secret information that is refreshed in each of a plurality of epochs. The first cryptographic device receives an epoch control signal, and adjusts at least one epoch responsive to the received epoch control signal. Refreshed secret information associated with an adjusted epoch is utilized to authenticate the first cryptographic device to at least a second cryptographic device, where the second cryptographic device and one or more additional cryptographic devices store respective portions of the secret information in a distributed manner. By way of example, the epoch control signal may comprise an epoch advance signal directing that the first cryptographic device advance from a current one of the epochs to a subsequent one of the epochs. In an illustrative embodiment, the first cryptographic device comprises an authentication token and the second cryptographic device comprises an authentication server.