Shared Secret Renewal for Network Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for securing confidential data over networks are inadequate in efficiently replacing shared secrets after a security breach, leading to potential unauthorized access and increased costs in changing shared secrets stored in devices.
Innovation Solution
A method and system for securely replacing shared secrets over networks, involving determining a security breach, generating a new shared secret and effective life, and transmitting it to both the authentication system and user devices, ensuring immediate expiration of compromised secrets and updating enrollment records.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If shared secrets are made difficult to change once included in the device, then security against unauthorized access is improved, but the time and cost to change shared secrets after a security breach increases
Solution Approach 1:
The shared secret is designed to be dynamically replaceable through a renewal message mechanism. The authentication system can transmit a renewal message containing a new shared secret to the device, allowing the secret to change from static to dynamic state when security breach is detected, thus resolving the contradiction between security stability and adaptability
Solution Approach 2:
The system performs preliminary action by establishing a renewal message transmission capability before security breach occurs. When breach is detected, the replacement process can immediately proceed without requiring device re-provisioning or complex authentication procedures, thus reducing time loss while maintaining security
2Reliability
If shared secrets are made difficult to change once included in the device, then security against unauthorized access is improved, but the cost to change shared secrets after a security breach increases
Solution Approach 1:
The device performs self-service by automatically receiving and implementing shared secret replacement through the renewal message mechanism. The authentication system initiates the replacement by transmitting the renewal message, and the device autonomously updates its shared secret without requiring manual intervention, technical support, or expensive re-provisioning services
Solution Approach 2:
The patent replaces the mechanical/physical process of changing shared secrets (which would require device re-provisioning, hardware manipulation, or technical support intervention) with an electronic information transmission mechanism. The renewal message carries the new shared secret digitally, substituting complex physical replacement procedures with simple data transmission, thus reducing cost
3Device complexity
If mechanisms are not available for notifying the web site operator that the requested access is effectively unauthorized, then device complexity is reduced, but the risk of unauthorized confidential data retrieval increases
Solution Approach 1:
The system implements feedback by notifying the website operator when coerced access is detected. The authentication mechanism provides feedback signals to the operator about the nature of the access attempt, enabling the operator to take appropriate actions. This feedback loop adds minimal complexity while effectively preventing unauthorized data retrieval
Data Source
AI summary
A method for replacing a shared secret over a network is provided that includes determining that a security breach could have occurred, determining that a shared secret of a user is to be replaced, and transmitting a renewal message to an authentication system requesting a new shared secret and an associated effective life for the user. Moreover, the method includes generating a new shared secret and an associated effective life at the authentication system for the user, and replacing the shared secret and associated effective life in an enrollment data record of the user with the new shared secret and associated effective life. Furthermore, the method includes transmitting the new shared secret and associated effective life to a communications device associated with the user, and replacing a shared secret and associated effective life stored in the communications device with the new shared secret and associated effective life.


