Secure Container Authorization for Multi-Provider Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure information storage devices are specialized in specific types of strong authentication (OTP, CS, PKI) and architectures (centralized or decentralized), leading to high costs and cumbersome management due to lack of mutualization among service providers, as each device is tailored for a particular method and infrastructure, limiting flexibility and efficiency in application deployment.
Innovation Solution
A method where an entity manages secure information storage devices by placing an authorization of communication in a secure container within the device, allowing third parties to customize and access the container independently, enabling multiple authentication methods and architectures without requiring re-implementing the device's infrastructure, and allowing for revocation of access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure information storage devices are specialized in specific authentication types and architectures, then authentication reliability is improved, but device complexity and management difficulty increase
Solution Approach 1:
The secure information storage device is designed to support multiple authentication methods (OTP, CS, PKI) and both centralized and decentralized architectures through a universal interface. The device contains a secure container that can store different types of authentication data and can operate in different architectural modes, making it adaptable to various service providers and authentication requirements without requiring specialized hardware for each type.
2Reliability
If each service provider implements dedicated authentication devices, then authentication security is improved, but cost efficiency deteriorates due to lack of mutualization
Solution Approach 1:
Multiple service providers can share the same secure information storage device through a mutualization mechanism. The device contains a secure container that can be accessed by different service providers according to their specific needs, allowing them to share the hardware infrastructure while maintaining their own authentication security requirements. This eliminates the need for each provider to deploy separate dedicated devices, reducing overall costs while maintaining security.
3Reliability
If authentication devices are hardware-specific to each service provider, then authentication control is improved, but ease of operation deteriorates due to cumbersome management
Solution Approach 1:
An intermediary management system is introduced that handles the coordination between multiple service providers and the shared secure information storage device. This intermediary layer manages access control, authentication operations, and device configuration, allowing service providers to operate with simplified interfaces while maintaining robust control mechanisms. The intermediary abstracts the complexity of hardware-specific operations, making the system easier to operate while preserving authentication control.
Data Source
AI summary
The disclosure relates to a method for communication between a secure information storage device and at least one third party with which information is exchanged. An entity ensures the management of a plurality of secure information storage devices to which said device pertains. The method includes the following steps: the entity places, in a secure container which is arranged in the device and specific to a third party, an authorization for communication between the secure container and the given third party; the entity sends an identifier of the device, an address of the device, an identifier of the secure container, and the authorization to communicate, to the give third party; the given third party attempts to establish communication with the secure container, using the address of the device, the identifier of the device, the identifier of the secure container, and the authorization to communicate; and, before accepting said communication, the device checks that the authorization to communicate transmitted by the third party is acceptable in view of the authorization to communicate previously placed in the secure container by the entity.


