Hardware U2F Authentication for Multi-Tenant Cloud Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing systems face challenges in securely authenticating users, particularly in multi-instance and multi-tenant frameworks, where data volumes are vast and diverse, leading to difficulties in managing user access and ensuring security against attacks like man-in-the-middle attacks.

Innovation Solution

Implementing a universal 2nd factor (U2F) authentication framework as a service, utilizing hardware devices such as USB or NFC security tokens certified by the FIDO Alliance, to provide cryptographic security and tamper-proof authentication processes, enhancing user authentication with login/password combinations and hardware-based verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional password-based authentication is used, then ease of operation is maintained, but security reliability deteriorates due to vulnerability to attacks

Engineering Contradiction:
Improveauthentication securityVSAvoiduser authentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces hardware-based authentication devices (such as USB security tokens, NFC tags, or biometric sensors) as intermediary elements between the user and the authentication system. These devices store cryptographic keys or biometric data locally, enabling secure authentication without requiring users to transmit or manage passwords. The hardware device acts as a mediator that proves user identity through cryptographic challenges, eliminating the need for password-based authentication while maintaining ease of use.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/password-based authentication system with a hardware-based cryptographic system. Instead of relying on text-based passwords that can be intercepted or guessed, the system uses hardware security modules to perform cryptographic operations. This substitution maintains user convenience (as the hardware device is simply plugged in or activated) while providing superior security through hardware-protected cryptographic functions that are resistant to software-based attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If hardware-based authentication devices are deployed, then authentication security is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex cryptographic authentication logic from the server-side system and places it within the hardware authentication device itself. The hardware device contains the cryptographic keys and authentication algorithms, eliminating the need for complex server-based authentication infrastructure. This extraction simplifies the overall system architecture by removing the need for centralized credential storage and complex authentication protocols, while maintaining high security through hardware-protected cryptographic operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent designs the hardware authentication device to serve multiple functions: storing cryptographic keys, performing authentication challenges, and providing user identification. This multi-functional approach consolidates what would otherwise require separate components (key storage, authentication logic, user verification) into a single universal device. The hardware device can be used across multiple systems and services, providing consistent authentication without requiring system-specific complex integration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If multifactor authentication is implemented, then authentication reliability is improved, but authentication time increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary authentication actions by pre-storing cryptographic keys and authentication data within the hardware device before the actual authentication event. When authentication is required, the hardware device can immediately retrieve and use the pre-stored credentials without requiring real-time complex computations or multiple sequential verification steps. This preliminary preparation eliminates the need for time-consuming authentication processes while maintaining security through hardware-protected cryptographic operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables continuous authentication by maintaining the hardware device in an active state ready for immediate authentication. The hardware device continuously holds the cryptographic keys and authentication logic in memory, allowing for instant authentication responses without requiring device initialization or key retrieval time. This continuous readiness eliminates authentication delays while maintaining security through ongoing hardware-protected cryptographic operations.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS12445429B2System and method for authentication as a service
Publication Date: 2025.10.14 SERVICENOW INC
  • US12445429B2 patent drawing
  • US12445429B2 patent drawing
  • US12445429B2 patent drawing

AI summary

A computing system includes a server. The server is communicatively coupled to a data repository and is configured to store a data in the data repository. The server is further configured to receive a first authentication information, the first authentication information comprising a login and a password for an entity, and to receive a second authentication information, the second authentication information comprising at least one identifying information generated by a hardware authentication device. The server is further configured to execute a hardware-based authentication as a service process, the authentication as a service process configured to use the first and the second authentication information as input to authenticate the entity, and to provide computing resources to the entity if the entity is successfully authenticated.