Remote Trust Service Authentication via Secure Client ID

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computers are vulnerable to attacks such as dictionary and brute force attacks, leading to reduced user trust due to inadequate protection methods for sensitive data, which existing technologies have not effectively addressed.

Innovation Solution

Implementing a remote trust service that provides trust-related functions to client devices without the need for a local Trusted Platform Module, using a client identifier stored in a secure location inaccessible to the operating system and applications, to authenticate communications and manage security assets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a local Trusted Platform Module is implemented on client devices, then security and trust services are improved, but manufacturing costs increase and processing/memory resources are consumed

Engineering Contradiction:
ImprovesecurityVSAvoidmanufacturing costs
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent extracts the Trusted Platform Module functionality from the client device and relocates it to a remote server. The client device no longer requires local hardware-based trust environment, instead communicating with the remote TPM service over a network. This extraction eliminates the need for expensive security chips in each device while maintaining security functions centrally.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The remote TPM service provides universal trust services to multiple client devices through a centralized platform. A single remote server with TPM capabilities serves multiple clients, replacing the need for each individual device to have its own TPM module. This multi-functional approach consolidates security resources and reduces per-device manufacturing costs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a local Trusted Platform Module is implemented on client devices, then security and trust services are improved, but processing and memory resources on client devices are consumed

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts resource-intensive TPM operations from the client device and performs them remotely on the server. Cryptographic operations, key management, and trust verification are executed on the remote TPM service, freeing up the client device's processing and memory resources for other tasks while maintaining security functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If passwords or personal identification numbers are used for data protection, then ease of operation is improved, but security is worsened due to vulnerability to attacks

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary authentication mechanism using device identifiers and cryptographic signatures. Instead of relying on vulnerable passwords, the system uses hardware-based device identification and digital signatures as an intermediary layer for authentication. This mediator provides both ease of operation (automatic authentication) and enhanced security (cryptographic verification resistant to dictionary and brute force attacks).

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3210155B1Trust service for a client device
Publication Date: 2019.08.07 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3210155B1 patent drawingFigure 1
  • EP3210155B1 patent drawingFigure 2
  • EP3210155B1 patent drawingFigure 3

AI summary

Techniques for a trust service for a client device are described. In various implementations, a trust service is implemented remotely from a client device and provides various trust-related functions to the client device. According to various implementations, communication between a client device and a remote trust service is authenticated by a client identifier (ID) that is maintained by both the client device and the remote trust service. In at least some implementations, the client ID is stored on a location of the client device that is protected from access by (e.g., is inaccessible to) device components such as an operating system, applications, and so forth. Thus, the client ID may be utilized to generate signatures to authenticate communications between the client device and the remote trust service.