Silent Alarm Channels Using One-Time Passcode Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing silent alarm channel implementations require high-bandwidth communication channels and incur significant costs, making them unsuitable for use with one-time passcode authentication tokens, which operate under limited bandwidth and resource constraints.

Innovation Solution

The implementation of silent alarm channels using one-time passcode authentication tokens, where a message indicating a potential attack is combined with a tokencode to generate a one-time passcode, allowing for secure and stealthy transmission over low-bandwidth channels, utilizing authenticated encryption and forward-secure pseudorandom number generators to ensure persistence and undetectability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional cryptographic formats are used for silent alarm channels, then security and reliability are improved, but communication costs and bandwidth requirements increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The invention extracts only the essential security functionality from complex cryptographic formats, implementing silent alarm channels using minimal cryptographic primitives (one-time passcodes with authentication) that provide sufficient security without the bandwidth overhead of conventional cryptographic formats

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The invention changes the parameter of cryptographic format from conventional high-bandwidth formats to one-time passcode authentication tokens with limited bandwidth, achieving the same security objectives with reduced communication costs and lower bandwidth requirements

Inventive Principle:
Principle #35Parameter changes

2Reliability

If conventional cryptographic formats are used for silent alarm channels, then security and reliability are improved, but device complexity and resource requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidresource requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The invention extracts only the essential security functionality from complex cryptographic formats, implementing silent alarm channels using minimal cryptographic primitives (one-time passcodes with authentication) that provide sufficient security without the bandwidth overhead of conventional cryptographic formats

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The invention uses one-time passcodes that are discarded after single use, eliminating the need for complex key management systems and persistent cryptographic state, thereby reducing device complexity and resource requirements while maintaining security

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Loss of energy

If one-time passcode authentication tokens are used, then bandwidth and resource constraints are satisfied, but the ability to transmit secure messages is limited

Engineering Contradiction:
ImprovebandwidthVSAvoidsecure transmission capability
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The invention makes the one-time passcode authentication token serve multiple functions: both authentication and silent alarm channel transmission, eliminating the need for separate communication channels and maintaining secure transmission capability within the limited bandwidth of the token system

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The invention uses the one-time passcode as an intermediary carrier that embeds both authentication credentials and silent alarm messages, allowing secure transmission of multiple types of information through the limited bandwidth channel without compromising security

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of manufacture

If silent alarm channels are made undetectable, then stealthiness is improved, but the ability to detect attacks is compromised

Engineering Contradiction:
ImprovestealthinessVSAvoidattack detection
Core Design Contradiction:
Ease of manufactureVSDifficulty of detecting and measuring

Solution Approach 1:

The invention uses the one-time passcode as an intermediary carrier that embeds both authentication credentials and silent alarm messages, allowing secure transmission of multiple types of information through the limited bandwidth channel without compromising security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The invention implements a feedback mechanism where the authentication server monitors for anomalies in passcode usage patterns, enabling detection of compromised tokens or silent alarm activations without requiring the alarm itself to be detectable to the attacker

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9515989B1Methods and apparatus for silent alarm channels using one-time passcode authentication tokens
Publication Date: 2016.12.06 DELL EMC
  • US9515989B1 patent drawing
  • US9515989B1 patent drawing
  • US9515989B1 patent drawing

AI summary

Methods and apparatus are provided for silent alarm channels using one-time passcode authentication tokens. A message is transmitted indicating a potential attack on a protected resource by obtaining the message; combining the message with a tokencode generated by a security token to generate a one-time passcode; and transmitting the one-time passcode to a receiver. A plurality of the messages can be obtained in parallel, and the plurality of parallel messages can be combined with the tokencode to generate the one-time passcode. A subsequent message can optionally be generated by applying a hash function to a prior n-bit value to provide a counter identifying each message. The message optionally also comprises one or more additional bits to provide an annotation of the message.