Security Token With Mutable Software Key Expiry
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Biomedical devices face security risks due to lost or stolen hardware tokens, which can lead to unauthorized access and potential harm, especially in settings where revoking access is cumbersome, especially in non-networked devices without central control or internet access.
Innovation Solution
A security token system that includes a communication interface, an immutable hardware key, and a mutable software key with an expiry, allowing for secure access control and revocation mechanisms without the need for a persistent network connection, using a combination of hardware and software tokens for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a hardware token is used to control access to device modes, then access security is improved, but the security risk increases when the token is lost or stolen
Solution Approach 1:
The patent applies dynamics by making the software key mutable and time-limited rather than static. The software key stored in non-volatile memory can be updated, revoked, or set to expire automatically, transforming the security mechanism from a permanent state to a dynamic one that adapts to security requirements and token status changes.
Solution Approach 2:
The patent changes the parameter of key validity by introducing an expiry mechanism. The software key includes validity period information that automatically limits its usefulness over time, and the system can modify key parameters (such as revoking access) without replacing the entire hardware token, thereby reducing the impact of token loss or theft.
2Reliability
If manual revocation of hardware tokens is implemented, then security control is improved, but the operational complexity increases especially in non-networked environments
Solution Approach 1:
The patent implements self-service by enabling the software key to automatically expire based on pre-configured time conditions without requiring manual intervention. The device autonomously manages key validity periods and can revoke access locally, eliminating the need for complex manual revocation processes or continuous network connectivity to central control systems.
Solution Approach 2:
The patent applies preliminary action by pre-configuring key expiry conditions and validity periods before the token is used. The software key is provisioned with expiration information in advance, allowing the system to automatically enforce time-limited access and simplify revocation without requiring real-time network communication or manual updates when tokens need to be revoked.
3Object-affected harmful factors
If a software key with expiry is implemented, then the security risk from lost tokens is reduced, but the device complexity increases
Solution Approach 1:
The patent merges the hardware token with a software key stored in the device's non-volatile memory, creating a combined authentication mechanism. The software key is integrated into the existing hardware token infrastructure, allowing the system to leverage existing hardware while adding software-based time-limited security features without requiring entirely separate systems.
Solution Approach 2:
The patent uses copying by storing a software key (which can be a digital copy or representation of authentication credentials) in non-volatile memory alongside or instead of traditional hardware token data. This software copy can be independently managed, updated, or expired without affecting the physical hardware token, thereby reducing the security impact of token loss while adding manageable complexity through software-based control.
Data Source
AI summary
A security token is provided having a communication interface with a communication transceiver; a circuit having encoded thereon an immutable hardware key; and a tangible, nonvolatile memory, the nonvolatile memory having stored thereon a mutable software key, the mutable software key including a cryptographic key and an expiry for the cryptographic key.


