Smart Token Hidden Secrets Secure Volume Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current dual-factor authentication systems using security tokens face limitations such as requiring the same password for multiple systems, vulnerability to loss or damage of the token, lack of group access management, reliance on complex software for access control, and susceptibility to software breaches.
Innovation Solution
A system utilizing a portable smart-token device that generates random encryption keys for each Secure Volume, storing these keys as 'Hidden Secrets' in the volume headers, allowing access with a PIN and enabling Master and Grand Master tokens, as well as user groups, to manage and access encrypted data independently of conventional security programs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the token stores a unique password for each system, then access security is improved, but the token requires more internal memory and the number of accessible systems is limited
Solution Approach 1:
The patent extracts the password storage function from the token by introducing a separate password server. The token only stores a unique identifier (token ID), while all passwords are stored externally on the password server. This allows unlimited systems to be accessed without increasing token memory requirements, as each system's password is retrieved from the server during authentication.
2Ease of operation
If the token is used to secure multiple systems with the same password, then ease of operation is improved, but security is worsened as anyone with the password gains access to the entire system
Solution Approach 1:
The patent segments the authentication process into two independent parts: the token (containing unique token ID) and the password server (containing system-specific passwords). Each system has its own password stored separately on the server, while the token remains unchanged. This segmentation allows the token to be reused across unlimited systems without compromising security, as each system's password is independently stored and retrieved during authentication.
3Ease of operation
If conventional security software is used to control access, then ease of operation is improved, but the system becomes vulnerable to software breaches and complex management
Solution Approach 1:
The patent replaces the software-based access control mechanism with a hardware-based solution. Instead of using complex software programs to manage authentication, the system uses a physical security token with a unique identifier that combines with a password server to provide access control. This hardware-based approach eliminates vulnerabilities associated with software breaches and simplifies management, as the token physically embodies the authentication credential.
Data Source
AI summary
A system for encrypting Secure Volumes using an encryption key which is saved in the open after being encoded inside a hardware token device utilizing a secure secret which is stored inside the device, and which never leaves the device. The encrypted volume can be accessed again only after a hardware token has decoded this encryption key. The system also provides means whereby the holder of a Master token and the holder of a Grand Master token may also have access to the volume as long as the user token was previously registered to the Master token, and the Master Token was previously registered to the Grand master token before the secured volume was encrypted. Also, the system allows members of user groups so designated at the time the volume is encrypted, to be able to have access to the volume as long as their token was previously registered with the same Master Token as the user that encrypted the volume and as long as the token encrypting the volume was also a member of the authorized user group.


