Secure Cryptoprocessor for Authorization Requests

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current two-factor authentication methods, such as smart cards, are costly, prone to user errors, and require additional hardware, while Bluetooth devices lack adequate security protections, making them inadequate for secure authorization processes.

Innovation Solution

A secure cryptoprocessor on an additional device, local or remote, computes responses to authorization requests based on protected credentials, providing secure authentication and authorization while displaying relevant information to the user for assent, thus eliminating the need for physical tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If smart cards are used for two-factor authentication, then security credentials are protected, but cost and hardware requirements increase

Engineering Contradiction:
Improvesecurity credential protectionVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces physical smart cards with a software-based secure cryptoprocessor that replicates the authentication functionality. The secure cryptoprocessor stores protected authorization credentials and computes authentication responses without requiring physical token hardware, thus copying the essential function of smart cards while eliminating hardware dependencies

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent substitutes the mechanical/physical smart card system with an electronic software-based system. The secure cryptoprocessor runs as software on standard devices, replacing the need for physical smart card readers and tokens with electronic credential verification processes

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Device complexity

If Bluetooth devices are used for authentication, then hardware requirements are reduced, but security credential protection is inadequate

Engineering Contradiction:
Improvehardware requirementsVSAvoidsecurity credential protection
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces a secure cryptoprocessor as an intermediary component that mediates between the requesting device and the authorization server. This cryptoprocessor acts as a trusted intermediary that securely stores credentials and performs cryptographic operations, bridging the security gap between standard devices and secure authentication requirements

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple smart cards are issued for multiple purposes, then authorization coverage is improved, but user management complexity increases

Engineering Contradiction:
Improveauthorization coverageVSAvoiduser management
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements a universal secure cryptoprocessor system that can handle multiple authorization purposes within a single software platform. The system stores protected credentials for multiple devices and purposes, allowing users to manage diverse authentication needs through one unified interface rather than multiple separate physical cards

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines multiple authorization functions and credentials into a single secure cryptoprocessor system. Instead of requiring separate smart cards for different purposes, the system merges multiple credential types and authorization scopes into one integrated software-based solution that manages all credentials centrally

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9825944B2Secure cryptoprocessor for authorizing connected device requests
Publication Date: 2017.11.21 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9825944B2 patent drawing
  • US9825944B2 patent drawing
  • US9825944B2 patent drawing

AI summary

A computing device described herein utilizes a secure cryptoprocessor of the computing device to compute a response to a request for authorization received from another local or remote device. The secure cryptoprocessor computes the response based on protected authorization credentials stored by the secure cryptoprocessor for one or more devices. The computing device then provides the computed response to the other device to cause the other device to grant or deny authorization. The computing device may also display information associated with the request for authorization, receive input indicating approval of the request, and utilize the secure cryptoprocessor in response to the received input.