Smart Token Hidden Secrets Secure Volume Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current dual-factor authentication systems using security tokens face limitations such as requiring the same password for multiple systems, vulnerability to loss or damage of the token, lack of group access management, reliance on complex software for access control, and susceptibility to software breaches.

Innovation Solution

A system utilizing a portable smart-token device that generates random encryption keys for each Secure Volume, storing these keys as 'Hidden Secrets' in the volume headers, allowing access with a PIN and enabling Master and Grand Master tokens, as well as user groups, to manage and access encrypted data independently of conventional security programs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the token stores a unique password for each system, then access security is improved, but the token requires more internal memory and the number of accessible systems is limited

Engineering Contradiction:
Improveaccess securityVSAvoidnumber of accessible systems
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extracts the password storage function from the token by introducing a separate password server. The token only stores a unique identifier (token ID), while all passwords are stored externally on the password server. This allows unlimited systems to be accessed without increasing token memory requirements, as each system's password is retrieved from the server during authentication.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If the token is used to secure multiple systems with the same password, then ease of operation is improved, but security is worsened as anyone with the password gains access to the entire system

Engineering Contradiction:
Improveease of loginVSAvoidaccess security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication process into two independent parts: the token (containing unique token ID) and the password server (containing system-specific passwords). Each system has its own password stored separately on the server, while the token remains unchanged. This segmentation allows the token to be reused across unlimited systems without compromising security, as each system's password is independently stored and retrieved during authentication.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If conventional security software is used to control access, then ease of operation is improved, but the system becomes vulnerable to software breaches and complex management

Engineering Contradiction:
Improveaccess controlVSAvoidsoftware breach vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the software-based access control mechanism with a hardware-based solution. Instead of using complex software programs to manage authentication, the system uses a physical security token with a unique identifier that combines with a password server to provide access control. This hardware-based approach eliminates vulnerabilities associated with software breaches and simplifies management, as the token physically embodies the authentication credential.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8656179B2Using hidden secrets and token devices to create secure volumes
Publication Date: 2014.02.18 BILLINGS ROGER E
  • US8656179B2 patent drawing
  • US8656179B2 patent drawing
  • US8656179B2 patent drawing

AI summary

A system for encrypting Secure Volumes using an encryption key which is saved in the open after being encoded inside a hardware token device utilizing a secure secret which is stored inside the device, and which never leaves the device. The encrypted volume can be accessed again only after a hardware token has decoded this encryption key. The system also provides means whereby the holder of a Master token and the holder of a Grand Master token may also have access to the volume as long as the user token was previously registered to the Master token, and the Master Token was previously registered to the Grand master token before the secured volume was encrypted. Also, the system allows members of user groups so designated at the time the volume is encrypted, to be able to have access to the volume as long as their token was previously registered with the same Master Token as the user that encrypted the volume and as long as the token encrypting the volume was also a member of the authorized user group.