Secure Identity Processing Area Automates Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Authenticating new computing devices within a network is labor-intensive and time-consuming, relying on human intervention with shared secrets, which is insecure and costly, especially in environments requiring increased security.

Innovation Solution

Implementing a Secure Identity Processing Area (SIPA) on each computing device to store a persistent identity, allowing automated authentication and secure bootstrapping without human intervention, using cryptographic operations to derive and manage security domain access credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual authentication with shared secrets is used, then authentication can be performed, but it is labor intensive and time consuming

Engineering Contradiction:
Improveauthentication speedVSAvoidtime for manual authentication
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The computing device performs self-authentication by automatically generating and using its own persistent identity credentials. The device autonomously derives credentials from its persistent identity and presents them to the security domain without requiring manual intervention from trusted employees, thereby eliminating the time-consuming manual authentication process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The persistent identity is stored on the computing device before it needs to join the security domain. This pre-stored identity enables the device to automatically generate and present credentials when authentication is required, eliminating the need for manual setup and reducing authentication time.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If shared secrets are used for authentication, then authentication can be established, but security reliability is compromised due to human error

Engineering Contradiction:
Improveauthentication securityVSAvoidhuman error in secret management
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the shared secret dependency from the authentication system by introducing device-specific persistent identities. Each device has its own unique credentials derived from its persistent identity, eliminating the need for shared secrets that are vulnerable to human error and compromise.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The persistent identity acts as an intermediary between the computing device and the authentication system. It provides a secure, device-specific basis for credential generation that eliminates direct reliance on shared secrets and human-managed authentication mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If trusted employees manually authenticate each device, then authentication can be performed, but operational costs increase

Engineering Contradiction:
Improveauthentication simplicityVSAvoidauthentication efficiency
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The computing device performs self-authentication without requiring trusted employees to manually intervene. The device automatically uses its persistent identity to derive and present credentials to the security domain, eliminating the operational burden and costs associated with manual authentication processes.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If shared secrets are distributed to employees, then authentication can be performed, but security is reduced due to potential disclosure

Engineering Contradiction:
Improveauthentication accessibilityVSAvoidsecret security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent removes the shared secret distribution model entirely by implementing device-specific persistent identities. Each device generates its own unique credentials from its persistent identity, eliminating the need to distribute secrets to employees and the associated security risks.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7669235B2Secure domain join for computing devices
Publication Date: 2010.02.23 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7669235B2 patent drawing
  • US7669235B2 patent drawing
  • US7669235B2 patent drawing

AI summary

A technique is provided for acquiring security domain access credentials on a computing device. The security domain access credentials are acquired by storing a persistent identity on the computing device, and deriving data that includes the security domain access credentials from the persistent identity. The derived data is transferred to a security domain to allow the computing device to join the security domain.