Obfuscated Authentication State Machine for Key Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems in electronic devices are vulnerable to key compromise and misuse, as public-key cryptography can be compromised if keys are lost or if the authentication procedure becomes known, leading to potential unauthorized access.
Innovation Solution
The implementation of obfuscated executable instructions for authentication that require a signal from a certifying authority, combined with a physically unclonable function and biometric authentication, to ensure secure and unique device identification, thereby protecting authentication keys and procedures from reverse engineering and misuse.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If public-key cryptography is used for authentication, then authentication capability is provided, but security is compromised if keys are lost or authentication procedure becomes known
Solution Approach 1:
The patent extracts the authentication procedure and keys from the device memory into a separate obfuscated state machine that can be distributed. The actual authentication logic is taken out of the vulnerable device environment and placed in a controlled external entity, reducing the risk of key compromise within the device.
Solution Approach 2:
The patent introduces an obfuscated state machine as an intermediary between the authentication request and the actual verification process. This intermediary obfuscates the authentication procedure, making it difficult to reverse engineer while maintaining security. The state machine acts as a mediator that protects the underlying cryptographic keys and procedures.
2Reliability
If authentication procedure is made secure through obfuscation, then resistance to reverse engineering is improved, but system complexity increases
Solution Approach 1:
The patent creates a simplified obfuscated state machine that copies only the essential authentication logic needed for verification. Rather than obfuscating the entire authentication system, a streamlined version is created that maintains security while reducing complexity. The state machine is a simplified representation that captures only the necessary authentication states and transitions.
3Ease of operation
If keys are stored in device memory for authentication, then authentication function is enabled, but vulnerability to misuse and misplacement increases
Solution Approach 1:
The patent segments the authentication system into separate components: the obfuscated state machine containing the authentication procedure and the actual cryptographic keys stored securely in device memory. This segmentation allows the authentication logic to be updated and distributed independently from the keys, reducing the risk of key misuse while maintaining ease of operation.
Data Source
AI summary
Embodiments of the present invention are directed toward authentication systems, devices, and methods. Obfuscated executable instructions may encode an authentication procedure and protect an authentication key. The obfuscated executable instructions may require communication with a remote certifying authority for operation. In this manner, security may be controlled by the certifying authority without regard to the security of the electronic device running the obfuscated executable instructions.


