Multi-Factor Certificate Authority Server Identity Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current two-factor authentication methods in network-based data processing are complex and costly, often requiring separate validation of device and user identities, which can lead to unauthorized access if the binding between the two factors is not checked, making them inefficiently used in industry applications.

Innovation Solution

Issuing multi-factor digital security certificates that bind device and user identities together at provisioning time, using a certificate authority server to digitally sign the certificate request with a cryptographic key, ensuring that both factors are associated and validated within a single authentication process, thereby reducing the need for external database queries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate validation of device and user identities is performed in traditional two-factor authentication, then device and user verification can be completed, but the authentication process becomes complex and costly requiring multiple database queries

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines device identity verification and user identity verification into a single integrated authentication process. The certificate authority issues a certificate that contains both the device identifier and user identifier, allowing both validations to occur simultaneously in one authentication transaction rather than requiring separate validation steps and multiple database queries.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The binding between device identity and user identity is established in advance during certificate issuance by the certificate authority. This preliminary action of pre-binding identities eliminates the need for complex runtime validation logic and multiple database queries during the authentication process, as the relationship is already certified in the issued certificate.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If binding between device and user factors is checked in traditional two-factor authentication, then security against unauthorized access is improved, but additional validation and database queries are required increasing cost and complexity

Engineering Contradiction:
Improvebinding verification securityVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the binding verification function into the certificate structure itself. The certificate contains both identities and a cryptographic binding between them, issued by a trusted certificate authority. This allows binding verification to occur as part of the standard certificate validation process without requiring separate validation steps or additional database queries, thus maintaining security while improving efficiency.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The certificate authority acts as an intermediary that pre-establishes and certifies the binding between device and user identities. By introducing this trusted intermediary during certificate issuance, the system eliminates the need for application-level binding verification logic and database queries, as the binding is already authenticated by the trusted authority.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If traditional two-factor authentication without binding check is used, then authentication process is simpler, but attackers can use stolen devices with stolen user identities causing unauthorized access

Engineering Contradiction:
Improveauthentication simplicityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent combines device identity and user identity into a single certificate that requires both factors to be present and correctly bound for authentication to succeed. This merging ensures that even if an attacker obtains either the device or user credentials separately, they cannot authenticate without both factors in their correct bound relationship, thus preventing unauthorized access while maintaining operational simplicity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The correct binding between device and user identities is established in advance during certificate issuance. This preliminary establishment of the binding relationship ensures that authentication is secure against credential theft while keeping the authentication process simple, as the binding verification is integrated into the certificate validation rather than requiring separate complex checks.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2842258B1Multi-factor certificate authority
Publication Date: 2017.03.01 INTEL CORP
  • EP2842258B1 patent drawingFigure 1
  • EP2842258B1 patent drawingFigure 2
  • EP2842258B1 patent drawingFigure 3

AI summary

Disclosed herein is a certificate authority server configured to provide multi-factor digital certificates. A processor readable medium may include a plurality of instructions configured to enable a certificate authority server of a certificate authority, in response to execution of the instructions by a processor, to receive a request to provide a multi-factor digital security certificate by digitally signing a certificate request having a plurality of factors and a cryptographic key, wherein a first of the plurality of factors is an identifier of a device and a second of the plurality of factors is an identifier of a user of the device. The instructions are also configured to enable the certificate authority server to associate the cryptographic key with the plurality of factors and issue the digital security certificate based on the certificate request. Also disclosed is a method of using a multi-factor digital certificate as part of the authorization process to implicitly bind the plurality of factors. Other embodiments may be described and claimed.