Obfuscated Authentication State Machine for Key Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems in electronic devices are vulnerable to key compromise and misuse, as public-key cryptography can be compromised if keys are lost or if the authentication procedure becomes known, leading to potential unauthorized access.

Innovation Solution

The implementation of obfuscated executable instructions for authentication that require a signal from a certifying authority, combined with a physically unclonable function and biometric authentication, to ensure secure and unique device identification, thereby protecting authentication keys and procedures from reverse engineering and misuse.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If public-key cryptography is used for authentication, then authentication capability is provided, but security is compromised if keys are lost or authentication procedure becomes known

Engineering Contradiction:
Improveauthentication securityVSAvoidkey compromise and unauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication procedure and keys from the device memory into a separate obfuscated state machine that can be distributed. The actual authentication logic is taken out of the vulnerable device environment and placed in a controlled external entity, reducing the risk of key compromise within the device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an obfuscated state machine as an intermediary between the authentication request and the actual verification process. This intermediary obfuscates the authentication procedure, making it difficult to reverse engineer while maintaining security. The state machine acts as a mediator that protects the underlying cryptographic keys and procedures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication procedure is made secure through obfuscation, then resistance to reverse engineering is improved, but system complexity increases

Engineering Contradiction:
Improveresistance to reverse engineeringVSAvoidauthentication system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a simplified obfuscated state machine that copies only the essential authentication logic needed for verification. Rather than obfuscating the entire authentication system, a streamlined version is created that maintains security while reducing complexity. The state machine is a simplified representation that captures only the necessary authentication states and transitions.

Inventive Principle:
Principle #26Copying

3Ease of operation

If keys are stored in device memory for authentication, then authentication function is enabled, but vulnerability to misuse and misplacement increases

Engineering Contradiction:
Improveauthentication functionalityVSAvoidkey misuse and misplacement
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authentication system into separate components: the obfuscated state machine containing the authentication procedure and the actual cryptographic keys stored securely in device memory. This segmentation allows the authentication logic to be updated and distributed independently from the keys, reducing the risk of key misuse while maintaining ease of operation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8566579B2Obfuscated authentication systems, devices, and methods
Publication Date: 2013.10.22 NATIONAL TECHNOLOGY & ENGINEERING SOLUTIONS OF SANDIA LLC
  • US8566579B2 patent drawing
  • US8566579B2 patent drawing
  • US8566579B2 patent drawing

AI summary

Embodiments of the present invention are directed toward authentication systems, devices, and methods. Obfuscated executable instructions may encode an authentication procedure and protect an authentication key. The obfuscated executable instructions may require communication with a remote certifying authority for operation. In this manner, security may be controlled by the certifying authority without regard to the security of the electronic device running the obfuscated executable instructions.