Segmented Key Authentication via Distributed Pairing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication systems are vulnerable to password theft due to reliance on user memory, remote hacking, and keylogger threats, with weak password protection and lack of robust security measures.
Innovation Solution
An authentication system utilizing a segmented pairing key distributed across multiple physical devices and tokens, requiring near-field communication for reconstitution and stored in volatile memory to prevent permanent storage and remote access, combined with encryption and scrambling to counter keyloggers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If authentication data is stored in non-volatile memory for permanent access, then ease of operation is improved, but security is worsened due to risk of copying and remote theft
Solution Approach 1:
The pairing key is divided into multiple segments distributed across different devices (primary mobile device, secondary mobile devices, tokens). This segmentation prevents any single device from containing the complete authentication data, thereby enhancing security while maintaining operational ease through distributed access.
Solution Approach 2:
The patent uses volatile memory to store authentication data temporarily during the authentication process. This short-living storage approach ensures that sensitive data is not permanently stored, reducing the risk of copying and remote theft, while still enabling smooth authentication operations during the active session.
2Ease of operation
If a master password protects all identifier/password pairs, then ease of operation is improved, but security is worsened because one compromised password grants access to all data
Solution Approach 1:
Instead of using a single master password, the system segments the pairing key into multiple parts stored in different devices. This eliminates the single point of failure associated with master passwords, as compromising one device does not grant access to the complete authentication data.
3Reliability
If physical objects like smart cards or USB keys are used for authentication, then security is improved, but ease of operation is worsened due to need for physical handling and card readers
Solution Approach 1:
The system uses mobile devices that users already possess and are familiar with, eliminating the need for specialized physical authentication objects like smart cards or USB keys. The mobile device serves multiple functions including storing key segments, communicating via NFC, and providing the user interface, thereby improving ease of operation while maintaining security.
4Ease of operation
If username/password pairs are entered in plain text, then ease of operation is improved, but security is worsened due to keylogger vulnerability
Solution Approach 1:
The system extracts the sensitive pairing key data from the user interface and stores it securely in the mobile device's memory. The authentication process uses this stored key segment without requiring the user to manually enter the sensitive data, thereby eliminating keylogger vulnerability while maintaining ease of operation through automatic authentication.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Provides robust protection against password theft by requiring physical proximity for key reconstitution, encrypting data, and scrambling passwords to evade keyloggers, ensuring secure access even if individual components are stolen.
Implementation Method 1
the main mobile device being configured to retrieve, via the near field communication module, the authentication data of the main token
Data Source
Figure 1
Figure 2
AI summary
The invention concerns an authentication system with at least one application accessible by a user via a computer and for which the access is controlled by an authentication datum, comprising a main mobile device and a main token in which at least one authentication datum is recorded, the main mobile device being configured to recover the authentication datum of the main token using a pairing key, characterised in that the pairing key is segmented into a plurality of segments, a first segment being recorded on the main mobile device and at least one other additional segment being recorded on a secondary mobile device and/or a secondary token, the main mobile device being configured to recover the additional segment or segments in order to reconstitute the pairing key and to present the reconstituted pairing key to the main token.