Mutual Authentication Hardware Token Non-Networked Device
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In non-networked architectures, managing user access and updating authentication credentials across multiple devices is tedious and difficult, especially in decentralized settings without central control, leading to inefficiencies and security vulnerabilities.
Innovation Solution
Implementing mutual authentication between a hardware access token and a reader device using a unique or pseudo-unique identifier, where the password is computed from the token and a group secret stored on the reader device, allowing access to onboard data structures and enabling secure operation modes without relying on centralized management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If each device stores all user credentials locally in a non-networked architecture, then devices can operate without network connection, but adding a new user requires manual updates to all devices which is tedious and time-consuming
Solution Approach 1:
The patent introduces a centralized server as an intermediary that stores user credentials and provides them to devices on demand. The server acts as a mediator between users and multiple devices, eliminating the need for manual credential distribution. When a new user is added, the server automatically provides credentials to authorized devices through the established protocol.
Solution Approach 2:
The system implements a feedback mechanism where devices communicate with the centralized server to obtain credentials. The server receives requests from devices, provides appropriate credentials, and receives feedback about authentication status. This automated feedback loop eliminates manual update processes and ensures all devices have current credentials.
2Ease of operation
If a centralized server is used to manage credentials, then credential management becomes automated and efficient, but the system requires network connection and centralized control which contradicts the non-networked requirement
Solution Approach 1:
The patent segments the system into distinct functional components: a centralized credential management server, reader devices with specific authentication functions, and a protocol layer that defines communication rules. This segmentation allows the server to handle credential management complexity while devices maintain simple, standardized authentication routines, reducing overall system complexity.
Solution Approach 2:
The patent creates a universal authentication protocol that can be implemented across multiple device types and platforms. The standardized interface allows different devices to work with the centralized server using the same credential management approach, simplifying deployment and reducing the complexity of implementing separate solutions for each device.
3Reliability
If manual update of all devices is required when adding new users, then system security is maintained through local credential storage, but the update process becomes tedious and difficult to implement as devices increase
Solution Approach 1:
The centralized server acts as an intermediary that automatically distributes credentials to devices when new users are added. Instead of manually updating each device, the administrator adds a user to the server, and the server handles credential distribution to all authorized devices through the established protocol, dramatically increasing user addition speed.
Solution Approach 2:
The system implements self-service credential distribution where devices automatically request and receive credentials from the centralized server when needed. This eliminates the need for manual intervention in the credential update process, allowing the system to automatically maintain security while enabling rapid user addition.
Data Source
AI summary
Systems and methods for performing mutual authentication between a hardware access token and a reader device are provided. The systems and methods include reading a unique or pseudo-unique identifier of the hardware access token and computing a password for the hardware access token based on the unique or pseudo-unique identifier and a group secret of the reader device.


