Secure Authentication System Using Cryptographic Key Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for authenticating users to access secured services are cumbersome, prone to unauthorized access due to compromised devices, and lack secure key distribution mechanisms, particularly in distributed computing environments.

Innovation Solution

A system and method for authenticating users that involves establishing a secure communication mechanism between an access device and a service provider using cryptographic processing, where credentials are encrypted and signed within a security boundary, verified by a digital certificate, and securely distributed to ensure only trusted devices access the network, incorporating RFID tokens and biometric sensors for secure credential entry.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional manual authentication methods are used, then users can access secured services, but the process becomes cumbersome and time-consuming

Engineering Contradiction:
Improveauthentication processVSAvoidauthentication time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-distributing cryptographic keys to authorized devices and pre-establishing trust relationships. When authentication is needed, the device can immediately present its credentials without manual intervention, as the authentication data has already been prepared and secured in advance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system enables devices to perform self-service authentication by automatically presenting cryptographic credentials to the access control device. The device independently verifies its own authorization status through cryptographic proof without requiring manual credential entry or administrator intervention.

Inventive Principle:
Principle #25Self-service

2Reliability

If cryptographic keys are distributed manually to devices, then secure access is established, but the process is cumbersome and error-prone

Engineering Contradiction:
Improvesecure accessVSAvoidkey distribution process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary key distribution mechanism where cryptographic keys are automatically distributed through a controlled channel between the access control device and authorized devices. This intermediary process eliminates manual key handling while maintaining security through cryptographic protocols and automated verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If credentials are entered through standard input devices, then users can provide authentication information, but the credentials may be compromised by hackers or viruses

Engineering Contradiction:
Improvecredential entryVSAvoidcredential security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the credential entry process from vulnerable software layers and standard input devices. By using dedicated secure input mechanisms that directly interface with the cryptographic module, the system removes credentials from the attack surface of the general-purpose computer system, preventing hackers or viruses from intercepting them through standard software interfaces.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces traditional mechanical input methods (keyboard, mouse) with secure cryptographic input mechanisms that operate at the hardware level. This substitution eliminates the vulnerability of credentials passing through software drivers and operating system layers, where they could be intercepted by malicious software.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If cryptographic processing is performed outside a security boundary, then authentication can be verified, but the credentials may be intercepted or compromised

Engineering Contradiction:
Improveauthentication verificationVSAvoidcredential interception
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements nesting by placing the cryptographic processing module within a protected security boundary that is itself embedded within the device architecture. This nested structure ensures that credentials and cryptographic operations occur in isolated, secure environments that are inaccessible to external attackers or malicious software running on the host system.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS8166296B2User authentication system
Publication Date: 2012.04.24 NXP BV
  • US8166296B2 patent drawing
  • US8166296B2 patent drawing
  • US8166296B2 patent drawing

AI summary

Techniques are provided for users to authenticate themselves to components in a system. The users may securely and efficiently enter credentials into the components. These credentials may be provided to a server in the system with strong authentication that the credentials originate from secure components. The server may then automatically build a network by securely distributing keys to each secure component to which a user presented credentials.