Secure Processor Credential Verification via Dual Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing online security systems are vulnerable to hacking due to the lack of verification of both the user and the server, particularly in phishing and man-in-the-middle attacks, where credentials are intercepted or compromised by malicious code.

Innovation Solution

Implementing a system that uses a secure processor with integrated authentication and cryptographic capabilities to verify both the user and the server through methods such as public key infrastructure, challenge/response protocols, and transport layer security, ensuring that credentials are only released after successful verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If credentials are transmitted in clear text for ease of operation, then authentication speed is improved, but security against interception and hacking is worsened

Engineering Contradiction:
Improveauthentication speedVSAvoidcredential interception
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the mechanical approach of transmitting credentials in clear text with cryptographic substitution. Credentials are transformed through cryptographic functions (hashing, encryption) before transmission, making them unintelligible to interceptors while maintaining authentication functionality. This substitution resolves the contradiction by preserving operational ease while eliminating the security vulnerability of clear text transmission.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces cryptographic protocols and secure communication channels as intermediaries between the user and server. These intermediaries transform the credential transmission process, adding layers of security (encryption, digital signatures, challenge-response mechanisms) that prevent direct interception while maintaining the authentication function. The intermediary layer resolves the contradiction by mediating between operational simplicity and security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If server identity verification is added to prevent phishing attacks, then security against fraudulent servers is improved, but system complexity is worsened

Engineering Contradiction:
Improvephishing attack resistanceVSAvoidauthentication system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing trusted server identities through digital certificates and public key infrastructure before the authentication transaction occurs. The server's identity is verified in advance through cryptographic validation of certificates, allowing the authentication process to proceed without requiring complex real-time verification mechanisms. This preliminary setup resolves the contradiction by reducing runtime complexity while maintaining strong phishing resistance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses digital certificates as cryptographic copies of server identity that can be verified without direct contact with the server. Instead of complex real-time identity verification, the system uses pre-generated cryptographic representations (certificates) that prove server identity. This copying approach resolves the contradiction by simplifying the verification process while maintaining strong security against phishing attacks.

Inventive Principle:
Principle #26Copying

3Reliability

If multi-factor authentication is implemented to strengthen security, then credential protection is improved, but user operation complexity is worsened

Engineering Contradiction:
Improvecredential protectionVSAvoiduser authentication steps
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple authentication factors into a unified cryptographic authentication process. Instead of requiring separate manual verification steps for each factor, the system combines them into integrated cryptographic operations (e.g., combining knowledge-based passwords with possession-based tokens through cryptographic protocols). This merging resolves the contradiction by maintaining strong multi-factor protection while reducing operational complexity through automated cryptographic verification.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8689290B2System and method for securing a credential via user and server verification
Publication Date: 2014.04.01 NXP BV
  • US8689290B2 patent drawing
  • US8689290B2 patent drawing
  • US8689290B2 patent drawing

AI summary

Systems and methods for securing a credential generated by or stored in an authentication token during an attempt to access a service, application, or resource are provided. A secure processor receives a credential from an authentication token and securely stores the credential. The secure processor then verifies the identity of the individual attempting to use the authentication token and cryptographically verifies the identity of the server being accessed. The credential is only released for transmission to the server if both the identity of the individual and the identity of the server are successfully verified. Alternatively, a secure connection is established between the secure processor and the server being accessed and a secure connection is established between the secure processor and a computing device. The establishment of the secure connections verifies the identity of the server. After the secure connections are established, the identity of the user is verified.