Processorless Hardware Token for Secure Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing hardware tokens for secure electronic connections are compute-intensive, leading to high power consumption and battery drain, and are vulnerable to differential power analysis attacks, while also being costly due to the presence of microprocessors and requiring compute-intensive processes on both tokens and authentication servers.
Innovation Solution
A processorless hardware token with a pre-produced sequence of one-time passwords stored in non-volatile memory, using a limited circuit board to retrieve and display passwords, which are then authenticated by an Authentication Server, reducing power consumption and production costs, and enhancing security by eliminating the need for microprocessors and sensitive seed management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a microprocessor is used to execute encryption or hash algorithms on the hardware token, then one-time passwords can be generated, but power consumption increases and battery life is reduced
Solution Approach 1:
The patent pre-computes and stores a sequence of one-time passwords in non-volatile memory during manufacturing, eliminating the need for microprocessor execution during operation. This preliminary action resolves the contradiction by performing the compute-intensive task before the device is deployed, thus reducing operational power consumption while maintaining password generation capability.
2Reliability
If a microprocessor is used on the hardware token, then cryptographic algorithms can be executed, but production costs increase
Solution Approach 1:
The patent extracts and removes the microprocessor from the hardware token, retaining only the essential non-volatile memory for storing pre-computed passwords. This extraction eliminates the costly microprocessor component while maintaining the core functionality of password generation, thereby reducing production costs without compromising reliability.
3Productivity
If a microprocessor executes cryptographic algorithms in real-time, then one-time passwords can be generated dynamically, but the system becomes vulnerable to differential power analysis attacks
Solution Approach 1:
The patent performs cryptographic computations in advance during manufacturing and stores the results in non-volatile memory, eliminating real-time execution that would expose the system to differential power analysis. This preliminary action resolves the vulnerability by removing the computational process that generates power consumption patterns, while maintaining password generation capability through stored pre-computed values.
4Productivity
If the Authentication Server processes hundreds of one-time passwords simultaneously, then authentication throughput increases, but compute-intensive processing causes time interval rollover and authentication failures
Solution Approach 1:
The patent pre-computes and stores sequences of one-time passwords on both the hardware token and the Authentication Server during manufacturing. This preliminary action enables the server to quickly retrieve and compare pre-computed passwords rather than performing real-time cryptographic operations, thereby maintaining high authentication throughput while preventing time interval rollover issues caused by compute-intensive processing delays.
Data Source
AI summary
A processorless hardware token provides a one-time password for user authentication. The processorless hardware token contains a non-volatile memory upon which is stored a pre-produced sequence of one-time passwords. The processorless hardware token uses limited circuitry on a circuit board to read from the non-volatile memory and display a one-time password associated with a current interval. The displayed one-time password is then used for authentication by an authentication server that compares the one-time password displayed on the processorless hardware token with a one-time password retrieved from a copy of the pre-produced sequence of one-time passwords stored on the Authentication Server.


