Secure Code Verification for Message Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing message authentication methods are vulnerable to attacks where an attacker can fake the secure boot of a client device, allowing fraudulent operations by mimicking the authentication process, leading to potential fraudulent activities.
Innovation Solution
A system comprising a client device and a security device that verifies the authenticity of codes stored on the client device, enabling secure message authentication only if the code is authorized, using cryptographic properties and secret data to ensure message integrity and prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If message authentication is performed using shared secret key and MAC, then message integrity is ensured, but the system becomes vulnerable to fake secure boot attacks
Solution Approach 1:
The patent applies preliminary action by verifying the authenticity of the code (secure boot verification) before performing message authentication. The security device checks whether the code stored in the client device is authentic using cryptographic verification, and only after successful verification does it enable the shared secret key to be used for message authentication. This prevents fake secure boot attacks because the authentication process is blocked at the code verification stage before the MAC generation can be compromised.
2Object-affected harmful factors
If code verification is added to the authentication process, then security against fake boot attacks is improved, but system complexity increases
Solution Approach 1:
The patent introduces a security device as an intermediary component that handles the code verification process. This security device acts as a mediator between the client device and the message authentication process. It verifies the authenticity of the code using cryptographic methods and controls whether the shared secret key can be accessed for MAC generation. By separating the code verification function into a dedicated security device, the patent adds security without significantly complicating the overall system architecture, as the security device operates as a distinct module with a specific function.
Data Source
AI summary
Systems, methods, circuits and computer-readable mediums for message authentication with secure code verification are provided. In one aspect, a system includes a client device storing a code and a security device coupled to the client device. The security device is configured to receive a property of the code generated by the client device, verify correctness of the property of the code based on information associated with an authorized code to determine that the code is authorized, the information being stored within the security device. In response to determining that the code is authorized, the security device enables to access data stored within the security device and generate a property of a message based on the data.


