Silent Alarm Channels Using One-Time Passcode Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing silent alarm channel implementations require high-bandwidth communication channels and incur significant costs, making them unsuitable for use with one-time passcode authentication tokens, which operate under limited bandwidth and resource constraints.
Innovation Solution
The implementation of silent alarm channels using one-time passcode authentication tokens, where a message indicating a potential attack is combined with a tokencode to generate a one-time passcode, allowing for secure and stealthy transmission over low-bandwidth channels, utilizing authenticated encryption and forward-secure pseudorandom number generators to ensure persistence and undetectability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional cryptographic formats are used for silent alarm channels, then security and reliability are improved, but communication costs and bandwidth requirements increase significantly
Solution Approach 1:
The invention extracts only the essential security functionality from complex cryptographic formats, implementing silent alarm channels using minimal cryptographic primitives (one-time passcodes with authentication) that provide sufficient security without the bandwidth overhead of conventional cryptographic formats
Solution Approach 2:
The invention changes the parameter of cryptographic format from conventional high-bandwidth formats to one-time passcode authentication tokens with limited bandwidth, achieving the same security objectives with reduced communication costs and lower bandwidth requirements
2Reliability
If conventional cryptographic formats are used for silent alarm channels, then security and reliability are improved, but device complexity and resource requirements increase
Solution Approach 1:
The invention extracts only the essential security functionality from complex cryptographic formats, implementing silent alarm channels using minimal cryptographic primitives (one-time passcodes with authentication) that provide sufficient security without the bandwidth overhead of conventional cryptographic formats
Solution Approach 2:
The invention uses one-time passcodes that are discarded after single use, eliminating the need for complex key management systems and persistent cryptographic state, thereby reducing device complexity and resource requirements while maintaining security
3Loss of energy
If one-time passcode authentication tokens are used, then bandwidth and resource constraints are satisfied, but the ability to transmit secure messages is limited
Solution Approach 1:
The invention makes the one-time passcode authentication token serve multiple functions: both authentication and silent alarm channel transmission, eliminating the need for separate communication channels and maintaining secure transmission capability within the limited bandwidth of the token system
Solution Approach 2:
The invention uses the one-time passcode as an intermediary carrier that embeds both authentication credentials and silent alarm messages, allowing secure transmission of multiple types of information through the limited bandwidth channel without compromising security
4Ease of manufacture
If silent alarm channels are made undetectable, then stealthiness is improved, but the ability to detect attacks is compromised
Solution Approach 1:
The invention uses the one-time passcode as an intermediary carrier that embeds both authentication credentials and silent alarm messages, allowing secure transmission of multiple types of information through the limited bandwidth channel without compromising security
Solution Approach 2:
The invention implements a feedback mechanism where the authentication server monitors for anomalies in passcode usage patterns, enabling detection of compromised tokens or silent alarm activations without requiring the alarm itself to be detectable to the attacker
Data Source
AI summary
Methods and apparatus are provided for silent alarm channels using one-time passcode authentication tokens. A message is transmitted indicating a potential attack on a protected resource by obtaining the message; combining the message with a tokencode generated by a security token to generate a one-time passcode; and transmitting the one-time passcode to a receiver. A plurality of the messages can be obtained in parallel, and the plurality of parallel messages can be combined with the tokencode to generate the one-time passcode. A subsequent message can optionally be generated by applying a hash function to a prior n-bit value to provide a counter identifying each message. The message optionally also comprises one or more additional bits to provide an annotation of the message.


