Shared Secret Renewal for Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing confidential data over networks are inadequate in efficiently replacing shared secrets after a security breach, leading to potential unauthorized access and increased costs in changing shared secrets stored in devices.

Innovation Solution

A method and system for securely replacing shared secrets over networks, involving determining a security breach, generating a new shared secret and effective life, and transmitting it to both the authentication system and user devices, ensuring immediate expiration of compromised secrets and updating enrollment records.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If shared secrets are made difficult to change once included in the device, then security against unauthorized access is improved, but the time and cost to change shared secrets after a security breach increases

Engineering Contradiction:
Improvesecurity against unauthorized accessVSAvoidtime to change shared secret
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The shared secret is designed to be dynamically replaceable through a renewal message mechanism. The authentication system can transmit a renewal message containing a new shared secret to the device, allowing the secret to change from static to dynamic state when security breach is detected, thus resolving the contradiction between security stability and adaptability

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary action by establishing a renewal message transmission capability before security breach occurs. When breach is detected, the replacement process can immediately proceed without requiring device re-provisioning or complex authentication procedures, thus reducing time loss while maintaining security

Inventive Principle:
Principle #10Preliminary action

2Reliability

If shared secrets are made difficult to change once included in the device, then security against unauthorized access is improved, but the cost to change shared secrets after a security breach increases

Engineering Contradiction:
Improvesecurity against unauthorized accessVSAvoidcost to change shared secret
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The device performs self-service by automatically receiving and implementing shared secret replacement through the renewal message mechanism. The authentication system initiates the replacement by transmitting the renewal message, and the device autonomously updates its shared secret without requiring manual intervention, technical support, or expensive re-provisioning services

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical/physical process of changing shared secrets (which would require device re-provisioning, hardware manipulation, or technical support intervention) with an electronic information transmission mechanism. The renewal message carries the new shared secret digitally, substituting complex physical replacement procedures with simple data transmission, thus reducing cost

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Device complexity

If mechanisms are not available for notifying the web site operator that the requested access is effectively unauthorized, then device complexity is reduced, but the risk of unauthorized confidential data retrieval increases

Engineering Contradiction:
Improveauthentication mechanism complexityVSAvoidunauthorized confidential data retrieval
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The system implements feedback by notifying the website operator when coerced access is detected. The authentication mechanism provides feedback signals to the operator about the nature of the access attempt, enabling the operator to take appropriate actions. This feedback loop adds minimal complexity while effectively preventing unauthorized data retrieval

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8990906B2Methods and systems for replacing shared secrets over networks
Publication Date: 2015.03.24 DAON TECH
  • US8990906B2 patent drawing
  • US8990906B2 patent drawing
  • US8990906B2 patent drawing

AI summary

A method for replacing a shared secret over a network is provided that includes determining that a security breach could have occurred, determining that a shared secret of a user is to be replaced, and transmitting a renewal message to an authentication system requesting a new shared secret and an associated effective life for the user. Moreover, the method includes generating a new shared secret and an associated effective life at the authentication system for the user, and replacing the shared secret and associated effective life in an enrollment data record of the user with the new shared secret and associated effective life. Furthermore, the method includes transmitting the new shared secret and associated effective life to a communications device associated with the user, and replacing a shared secret and associated effective life stored in the communications device with the new shared secret and associated effective life.