Secure CPU Password Authentication via Encrypted Objects
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional password protection methods are vulnerable to theft by keystroke loggers, memory scraping malware, and phishing attacks, and one-time password systems introduce additional security challenges due to the need for continuous protection of password streams.
Innovation Solution
The use of a Secure CPU architecture to encapsulate password generation, storage, and distribution within a 'Secure Object' that protects information from all software, including privileged software and malware, using cryptographic protection and integrity trees to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If passwords are stored and transmitted in clear text or with conventional encryption, then ease of operation is improved, but security against theft and unauthorized access deteriorates
Solution Approach 1:
The patent implements a nested structure where a Secure CPU contains a protected environment that in turn contains the password generation and storage mechanisms. This nested architecture allows the password system to be embedded within multiple layers of protection (CPU hardware → protected environment → password data), enabling conventional ease of use at the user level while maintaining strong security at the hardware level.
Solution Approach 2:
The patent introduces a Secure CPU as an intermediary component between the user and the password management system. This intermediary provides cryptographic protection and acts as a trusted mediator that generates and manages passwords without exposing them to the host operating system or potential malware, thus resolving the contradiction between ease of operation and security.
2Reliability
If one-time password systems are implemented, then security against password reuse is improved, but device complexity and protection requirements worsen
Solution Approach 1:
The Secure CPU is designed to autonomously generate and manage one-time password sequences without requiring external intervention or complex protection mechanisms. The protected environment within the Secure CPU self-manages the password stream, automatically generating new passwords for each authentication event while maintaining security without additional complexity in the host system.
Solution Approach 2:
The patent extracts the complex password generation and management logic from the host operating system and places it within the isolated Secure CPU environment. This extraction removes the burden of protecting the password stream from the main system, concentrating all protection requirements within the hardware-bound Secure CPU where they can be enforced through physical and logical security boundaries.
3Object-affected harmful factors
If passwords are protected from privileged software and malware, then security is improved, but ease of operation and system integration worsen
Solution Approach 1:
The Secure CPU acts as an intermediary that bridges the gap between security isolation and system integration. It provides protected password generation and management while maintaining controlled interfaces with the host operating system, allowing integration without compromising security. The intermediary nature enables the system to interact with the OS through defined protocols while keeping password data isolated from privileged software and malware.
Solution Approach 2:
The patent segments the password management functionality into a separate protected environment within the Secure CPU, distinct from the host operating system. This segmentation allows the password generation and storage functions to operate in isolation from untrusted software while maintaining necessary interfaces for authentication. The segmented architecture enables security protection without complete isolation, balancing security with operational ease.
Data Source
AI summary
A method and structure for authenticating users of a system that prevents theft of passwords and re-use of passwords. The method and structure use one-time passwords and a Secure CPU technology that cryptographically protects a software module known as a Secure Object from other software on a system. The method and structure generate and validate one-time passwords within Secure Objects and use a communications mechanism to securely communicate passwords or information used to generate passwords that makes use of cryptography and the protected and unprotected regions of a Secure Object to provide strong end-to-end security.


