Remote Trust Service Authentication via Secure Client ID
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computers are vulnerable to attacks such as dictionary and brute force attacks, leading to reduced user trust due to inadequate protection methods for sensitive data, which existing technologies have not effectively addressed.
Innovation Solution
Implementing a remote trust service that provides trust-related functions to client devices without the need for a local Trusted Platform Module, using a client identifier stored in a secure location inaccessible to the operating system and applications, to authenticate communications and manage security assets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a local Trusted Platform Module is implemented on client devices, then security and trust services are improved, but manufacturing costs increase and processing/memory resources are consumed
Solution Approach 1:
The patent extracts the Trusted Platform Module functionality from the client device and relocates it to a remote server. The client device no longer requires local hardware-based trust environment, instead communicating with the remote TPM service over a network. This extraction eliminates the need for expensive security chips in each device while maintaining security functions centrally.
Solution Approach 2:
The remote TPM service provides universal trust services to multiple client devices through a centralized platform. A single remote server with TPM capabilities serves multiple clients, replacing the need for each individual device to have its own TPM module. This multi-functional approach consolidates security resources and reduces per-device manufacturing costs.
2Reliability
If a local Trusted Platform Module is implemented on client devices, then security and trust services are improved, but processing and memory resources on client devices are consumed
Solution Approach 1:
The patent extracts resource-intensive TPM operations from the client device and performs them remotely on the server. Cryptographic operations, key management, and trust verification are executed on the remote TPM service, freeing up the client device's processing and memory resources for other tasks while maintaining security functionality.
3Ease of operation
If passwords or personal identification numbers are used for data protection, then ease of operation is improved, but security is worsened due to vulnerability to attacks
Solution Approach 1:
The patent introduces an intermediary authentication mechanism using device identifiers and cryptographic signatures. Instead of relying on vulnerable passwords, the system uses hardware-based device identification and digital signatures as an intermediary layer for authentication. This mediator provides both ease of operation (automatic authentication) and enhanced security (cryptographic verification resistant to dictionary and brute force attacks).
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Techniques for a trust service for a client device are described. In various implementations, a trust service is implemented remotely from a client device and provides various trust-related functions to the client device. According to various implementations, communication between a client device and a remote trust service is authenticated by a client identifier (ID) that is maintained by both the client device and the remote trust service. In at least some implementations, the client ID is stored on a location of the client device that is protected from access by (e.g., is inaccessible to) device components such as an operating system, applications, and so forth. Thus, the client ID may be utilized to generate signatures to authenticate communications between the client device and the remote trust service.