Off-Host Authentication System Segregating Credential Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Information Handling Systems (IHS) face security issues due to unauthorized access to the host processor during user authentication, which can manipulate the authentication process, compromising system security.
Innovation Solution
An external off-host authentication processing system is used, which segregates authentication processing from the host system, generating a system ID for the IHS without user prompting and storing authentication data in off-host memory, ensuring secure and segregated authentication through cryptographic protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If authentication credentials are verified by a host processor within the IHS, then authentication processing is integrated and convenient, but security is compromised because unauthorized persons may gain access to the processor and manipulate the authentication process
Solution Approach 1:
The authentication system is segmented into two independent parts: the host processor that handles user interface and the separate authentication processor that handles credential verification. This segmentation allows the authentication function to be isolated from potential compromises of the host processor, maintaining security while preserving operational convenience through the integrated user experience.
Solution Approach 2:
The authentication processing function is extracted from the host processor and placed in a dedicated authentication processor. This extraction removes the security vulnerability of having authentication credentials verified within the potentially compromised host environment, while the authentication processor remains closely integrated to maintain ease of operation.
2Reliability
If authentication processing is segregated from the host system in an external off-host system, then security is enhanced by preventing unauthorized access to the host processor, but device complexity increases
Solution Approach 1:
The authentication processor acts as an intermediary between the user and the host processor. It receives authentication credentials from the user, verifies them independently, and communicates only the verification result to the host processor. This intermediary approach enhances security by isolating credential verification from the host system while managing complexity through a well-defined communication interface.
Solution Approach 2:
The authentication processor is designed as a self-contained unit that can be physically or logically nested within or alongside the host system. This nesting approach allows the authentication function to be segregated for security purposes while maintaining a compact integrated form factor, thereby managing device complexity.
3Reliability
If the external off-host authentication processing system stores authentication data and system ID in off-host memory, then security is improved by preventing host processor access to sensitive data, but data access time may increase
Solution Approach 1:
Authentication data and system ID are pre-loaded into the off-host memory before authentication is needed. The authentication processor has direct access to this pre-positioned data, eliminating the need for real-time data retrieval from the host system during authentication. This preliminary action secures the data away from the host processor while maintaining fast access during the authentication process.
Data Source
AI summary
Systems and methods for providing object management for external off-host authentication processing systems are described. In some embodiments, a method may include: identifying, by an Information Handling System (IHS), raw data to be stored within an object in an off-host memory of an external off-host authentication processing system coupled to the IHS, wherein the external off-host authentication processing system provides a hardware environment segregated from the IHS; collecting authentication data from a user by prompting the user; generating a system identification (ID) that uniquely characterizes the IHS without prompting the user; and storing the authentication data, the system ID, and the raw data as part of the object in the off-host memory.


