Identity Certificate Service Multi-Factor Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Identity certificates are vulnerable to tampering and unauthorized access due to their storage in keychains or repositories, which can be easily compromised, leading to potential unauthorized access to protected resources.
Innovation Solution
Implementing multiple factor authentication in identity certificate services using cryptographically-obscured identifiers and certificates, where the service node validates both the certificate and identifiers to ensure only authorized access, preventing unauthorized certificate export and use on compromised devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If identity certificates are stored in keychains or repositories for easy access, then ease of operation is improved, but security is worsened due to vulnerability to tampering and unauthorized access
Solution Approach 1:
The patent segments the authentication process into multiple independent factors: something you have (certificate), something you know (password/PIN), and something you are (biometric data). This segmentation ensures that even if one factor is compromised through easy access to the keychain, the other factors remain protected, thereby maintaining security while preserving ease of operation through automated multi-factor authentication.
Solution Approach 2:
The patent implements nested security layers where biometric data is encrypted and stored within the secure enclave, the certificate is protected within the keychain, and both are guarded by password/PIN protection. This nested structure allows easy access to the outer layers while maintaining strong security at each nested level, resolving the contradiction between ease of operation and security.
2Ease of operation
If certificates are made easily accessible in keychains, then ease of operation is improved, but device compromise risk increases
Solution Approach 1:
The patent introduces the secure enclave as an intermediary layer between the keychain and the authentication process. The secure enclave acts as a protected mediator that verifies multiple authentication factors before allowing certificate usage, thereby maintaining ease of certificate accessibility while preventing unauthorized access even if the device is compromised.
Solution Approach 2:
The patent performs preliminary authentication actions by requiring multi-factor verification (certificate, password/PIN, and biometric data) before the certificate can be used. This preliminary action ensures that even if the keychain is accessible, the certificate cannot be misused without completing all authentication steps, thereby preventing device compromise while maintaining ease of operation.
3Device complexity
If single factor authentication is used for simplicity, then device complexity is reduced, but security is worsened due to unauthorized access risk
Solution Approach 1:
The patent implements self-service multi-factor authentication where the system automatically collects and verifies multiple authentication factors (certificate, password/PIN, biometric data) without requiring user intervention beyond providing the biometric data. This self-service approach maintains simplicity for the user while implementing strong security, effectively resolving the contradiction between device complexity and security.
Data Source
AI summary
Multiple factor authentication in an identity certificate service is disclosed. A certificate including a cryptographically-obscured identifier associated with the end entity is sent from an end entity to a service node. The service node uses both the certificate and the identifier to authenticate the end entity at least in part by comparing the identifier to a reference identifier. A service associated with the service node is accessed based at least in part on the authentication.


