Remote Authentication Token Administration via One-Time Password Codes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for administering authentication tokens are cumbersome, especially for remote users, as they often require physical transport to a security administrator or release of sensitive information, such as a PIN unlocking key (PUK), which can compromise security.
Innovation Solution
An authentication server generates a code based on a one-time password (OTP) that specifies an operation to be performed on the token, allowing remote configuration and management without revealing sensitive information, such as a PUK, by authenticating the code using shared secrets and cryptographic functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If physical transport of the token to a security administrator is required for PIN reset or unlocking, then security is maintained through physical control, but convenience and productivity deteriorate significantly for remote users
Solution Approach 1:
The patent introduces a remote administration system as an intermediary between the user and the physical token. This intermediary system allows administrators to perform operations (PIN reset, unlocking) remotely without requiring physical transport of the token, thus resolving the contradiction between security maintenance and operational convenience.
Solution Approach 2:
The patent replaces the mechanical/physical system of token transport and physical administration with a digital/telecommunications-based system. Administrators can remotely access and administer the token through a communication network, eliminating the need for physical transport while maintaining security through authenticated remote access.
2Ease of operation
If a PUK (PIN unlocking key) is provided to users for resetting PINs, then ease of operation improves, but security deteriorates due to the creation of a back-door that can be compromised
Solution Approach 1:
The patent extracts the PUK concept from the token itself and relocates it to a remote administration system. Instead of embedding a PUK in the token that could be compromised, the system provides PIN reset capabilities through a remote administration interface that authenticates administrators, thus maintaining security while enabling ease of operation.
Solution Approach 2:
The remote administration system acts as a secure intermediary that handles sensitive operations like PIN reset without exposing the token or its internal keys to unauthorized access. This intermediary approach eliminates the back-door risk associated with providing PUKs to users while maintaining operational ease.
3Reliability
If the token is locked after multiple incorrect PIN entries, then security is improved by preventing unauthorized access, but ease of operation deteriorates when the user needs to reset the PIN
Solution Approach 1:
The remote administration system serves as a mediator that can unlock locked tokens and reset PINs without requiring physical access to the token. This resolves the contradiction by providing a secure remote pathway for administrators to restore access while maintaining the security benefits of the lockout mechanism.
Solution Approach 2:
The patent replaces the physical lockout mechanism with a digital remote administration system that can programmatically reset PINs and unlock tokens. This substitution maintains the security purpose of lockout while providing much greater operational ease through remote access capabilities.
4Productivity
If administrators must physically access the token for configuration changes, then direct control is maintained, but productivity and ease of operation deteriorate for remote administrators
Solution Approach 1:
The patent replaces the physical administration process with a remote digital administration system. Administrators can perform configuration changes, PIN resets, and other operations remotely through a communication network, dramatically improving productivity while reducing the complexity of travel and physical access requirements.
Solution Approach 2:
The remote administration system provides universal access for administrators to perform multiple functions (PIN reset, unlocking, configuration changes) through a single remote interface, eliminating the need for separate physical processes and improving overall administrative efficiency.
Data Source
AI summary
Techniques are disclosed for performing operations in an authentication token or other cryptographic device in a system comprising an authentication server. In one aspect, a code generated by the authentication server is received in the cryptographic device. The code may have associated therewith information specifying at least one operation to be performed by the cryptographic device. The cryptographic device authenticates the code, and responsive to authentication of the code, performs the specified operation. If the code is not authenticated, the operation is not performed. The code may be determined as a function of a one-time password generated by the authentication server. The function may also take as an input an identifier of the operation to be performed.


