eToken Fingerprint Binding for Secure PKI Host Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems are vulnerable to attacks where attackers exploit PKI client stations using eTokens installed on other hosts, compromising security.
Innovation Solution
A system and method for binding eTokens to specific client devices using unique fingerprint data, regenerating device fingerprints, and verifying matches or acceptable differences to ensure secure data transmission only occurs on authorized devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If eTokens are made portable and usable across different hosts, then ease of operation is improved, but security is worsened due to vulnerability to attacks where attackers exploit PKI client stations using eTokens from other hosts
Solution Approach 1:
The system performs preliminary binding between the eToken and the host by generating and storing fingerprint data from host parameters before actual use. This pre-established binding relationship prevents the eToken from being used on unauthorized hosts, resolving the security vulnerability while maintaining portability within authorized contexts.
Solution Approach 2:
The patent introduces fingerprint data as an intermediary mechanism that mediates between the eToken and the host system. This fingerprint acts as a unique identifier and binding agent, allowing the system to verify whether the eToken is being used on its authorized host without compromising either portability or security.
2Reliability
If eTokens are bound to specific client devices using fingerprint data, then security is improved by preventing unauthorized use, but device complexity is worsened due to additional verification mechanisms
Solution Approach 1:
The system generates fingerprint data automatically from existing host parameters without requiring external intervention or complex setup procedures. The binding process is self-executing, using readily available system information to create the security binding, thereby minimizing the increase in device complexity while maintaining strong security.
3Reliability
If fingerprint verification is performed for every eToken operation, then security is improved, but productivity is worsened due to additional verification steps
Solution Approach 1:
The fingerprint binding is established once during initialization, and subsequent operations leverage this pre-established binding. The system does not perform complete verification for every operation but rather checks against the pre-stored fingerprint data, significantly reducing the overhead per operation while maintaining security.
Data Source
AI summary
A system and method for receiving secure data in a client device. In one embodiment, the method comprises (a) receiving a token having a token ID and a digital certificate generated by a certificate authority (CA) having client device fingerprint data generated from client device parameters, (b) accepting a request in the client device to provide secure data to the client device, (c) regenerating the client device fingerprint data from the client device parameters, (d) determining, in the client device, differences between the client device fingerprint data of the digital certificate from the regenerated client device fingerprint data, and (e) transmitting a request to a secure data service to provide secure data based upon the determination.


