Secure Processor Credential Verification via Dual Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing online security systems are vulnerable to hacking due to the lack of verification of both the user and the server, particularly in phishing and man-in-the-middle attacks, where credentials are intercepted or compromised by malicious code.
Innovation Solution
Implementing a system that uses a secure processor with integrated authentication and cryptographic capabilities to verify both the user and the server through methods such as public key infrastructure, challenge/response protocols, and transport layer security, ensuring that credentials are only released after successful verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If credentials are transmitted in clear text for ease of operation, then authentication speed is improved, but security against interception and hacking is worsened
Solution Approach 1:
The patent replaces the mechanical approach of transmitting credentials in clear text with cryptographic substitution. Credentials are transformed through cryptographic functions (hashing, encryption) before transmission, making them unintelligible to interceptors while maintaining authentication functionality. This substitution resolves the contradiction by preserving operational ease while eliminating the security vulnerability of clear text transmission.
Solution Approach 2:
The patent introduces cryptographic protocols and secure communication channels as intermediaries between the user and server. These intermediaries transform the credential transmission process, adding layers of security (encryption, digital signatures, challenge-response mechanisms) that prevent direct interception while maintaining the authentication function. The intermediary layer resolves the contradiction by mediating between operational simplicity and security requirements.
2Object-affected harmful factors
If server identity verification is added to prevent phishing attacks, then security against fraudulent servers is improved, but system complexity is worsened
Solution Approach 1:
The patent applies preliminary action by pre-establishing trusted server identities through digital certificates and public key infrastructure before the authentication transaction occurs. The server's identity is verified in advance through cryptographic validation of certificates, allowing the authentication process to proceed without requiring complex real-time verification mechanisms. This preliminary setup resolves the contradiction by reducing runtime complexity while maintaining strong phishing resistance.
Solution Approach 2:
The patent uses digital certificates as cryptographic copies of server identity that can be verified without direct contact with the server. Instead of complex real-time identity verification, the system uses pre-generated cryptographic representations (certificates) that prove server identity. This copying approach resolves the contradiction by simplifying the verification process while maintaining strong security against phishing attacks.
3Reliability
If multi-factor authentication is implemented to strengthen security, then credential protection is improved, but user operation complexity is worsened
Solution Approach 1:
The patent merges multiple authentication factors into a unified cryptographic authentication process. Instead of requiring separate manual verification steps for each factor, the system combines them into integrated cryptographic operations (e.g., combining knowledge-based passwords with possession-based tokens through cryptographic protocols). This merging resolves the contradiction by maintaining strong multi-factor protection while reducing operational complexity through automated cryptographic verification.
Data Source
AI summary
Systems and methods for securing a credential generated by or stored in an authentication token during an attempt to access a service, application, or resource are provided. A secure processor receives a credential from an authentication token and securely stores the credential. The secure processor then verifies the identity of the individual attempting to use the authentication token and cryptographically verifies the identity of the server being accessed. The credential is only released for transmission to the server if both the identity of the individual and the identity of the server are successfully verified. Alternatively, a secure connection is established between the secure processor and the server being accessed and a secure connection is established between the secure processor and a computing device. The establishment of the secure connections verifies the identity of the server. After the secure connections are established, the identity of the user is verified.


