Remote Secure Device Authentication via Local Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure device architectures that rely on local connections limit the deployment of secure applications, particularly in nomadic environments where physical presence is not feasible, as they fail to effectively implement two-factor authentication when the secure device is not physically present, such as in remote access scenarios.

Innovation Solution

A method that establishes a secure communication channel between a local and remote secure device using SIP protocol, where the local secure device authenticates the remote device, and a peer application on each device negotiates a data session, allowing the remote device to grant access only after verifying a PIN code entered by the user through the local secure device, ensuring mutual authentication and preserving the 'what you have' authentication factor.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a local connection is required between secure device and host computer, then two-factor authentication can be implemented, but device adaptability and remote access capability are limited

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a local secure device as an intermediary component that bridges the remote secure element and the accessing device. The local secure device holds the authentication factors and mediates the authentication process, enabling remote access while maintaining security. This intermediary approach allows the system to work across different device types without requiring direct physical connection between the secure element and accessing device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If secure device is remotely located, then device adaptability and remote access are improved, but implementation of two-factor authentication becomes unclear

Engineering Contradiction:
Improveremote access capabilityVSAvoidauthentication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the secure device functionality into two separate components: a remote secure element that provides secure data storage and processing, and a local secure device that provides the user interface and holds authentication factors. This segmentation allows the secure element to be remotely located and accessible from various devices while the local secure device remains with the user to provide physical authentication factors, thus maintaining two-factor authentication in remote scenarios.

Inventive Principle:
Principle #1Segmentation

3Reliability

If physical presence of secure device is required, then two-factor authentication is guaranteed, but ease of operation and remote access are reduced

Engineering Contradiction:
Improveauthentication securityVSAvoidremote access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The local secure device serves as an intermediary that the user physically possesses and interacts with, while the secure element remains remote. The user performs authentication operations locally (entering PIN, providing biometric) on the local secure device, which then communicates with the remote secure element. This maintains the physical presence requirement for authentication factors while enabling remote access to the secure services.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If multiple device formats are supported for remote access, then adaptability is improved, but security implementation complexity increases

Engineering Contradiction:
Improvedevice compatibilityVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication logic and security-critical functions into a standardized local secure device interface. The local secure device provides a uniform authentication mechanism that works regardless of the accessing device type (PC, mobile, TV, game station). This extraction of authentication functionality into a standardized component simplifies the overall system architecture and reduces complexity compared to implementing device-specific authentication solutions for each accessing device format.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2646942B1Method for providing a user with an authenticated remote access to a remote secure device
Publication Date: 2019.06.05 THALES DIS FRANCE SA
  • EP2646942B1 patent drawingFigure 1

AI summary

The invention relates to a method for providing a user with an authenticated remote access to a remote secure device (2), said remote access being initiated from a local accessing device (1), said remote secure device (2) embedding secure data related to a specific service, characterized in that it comprises establishing a mutual authentication between said remote secure device (2) and a local secure device (3) different from the local accessing device (l)so as the user of the local accessing device (3) is able to access to the secure data of the remote secure device (2).