Soft Token Passcode Encoding for Security Status Transmission
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional soft tokens on mobile devices are limited to providing only token codes and lack reliable communication with servers, making it difficult to enhance security by conveying additional information about the device's security status or detecting malicious activity.
Innovation Solution
A technique that combines token codes with sequences of auxiliary bits to create passcodes, which are displayed to users for manual transfer to a server, establishing a communication channel for both token codes and auxiliary bits, including a silent alarm to indicate malicious activity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If soft tokens only display token codes without additional communication, then the device complexity is low and ease of operation is maintained, but the ability to convey security status information and establish reliable communication with servers is limited
Solution Approach 1:
The patent combines token codes with auxiliary bits into a single passcode that is displayed to the user. This merging allows the soft token to convey both authentication information and device status information through one unified output, resolving the contradiction by enabling information-rich communication without requiring separate communication channels or increasing operational complexity.
Solution Approach 2:
The passcode serves multiple functions: it provides authentication verification through the token code portion and simultaneously transmits device security status information through the auxiliary bits portion. This multi-functionality allows a single communication mechanism to accomplish both authentication and status reporting, eliminating the need for additional communication infrastructure.
2Reliability
If the mobile device is suspected of being hacked and communicates with the server, then security monitoring is improved, but the communication itself may be compromised by malicious activity
Solution Approach 1:
The auxiliary bits act as an intermediary that carries device status information through the authentication process. Rather than requiring separate communication channels that could be independently compromised, the status information is embedded within the existing authentication communication flow, allowing security monitoring without creating additional vulnerable communication paths.
Solution Approach 2:
The soft token automatically includes current device status information in the passcode without requiring separate communication actions. The device monitors its own security state and self-reporting this information through the authentication process, enabling security monitoring while minimizing additional communication exposure to potential compromise.
3Loss of information
If multiple sequences of auxiliary bits are combined with token codes to create passcodes, then data transmission capability is improved, but the complexity of generating and processing passcodes increases
Solution Approach 1:
The passcode is segmented into distinct functional components: the token code portion for authentication and the auxiliary bits portion for status information. This segmentation allows the system to process and transmit different types of information through a unified structure, improving data transmission capability while maintaining manageable complexity through clear functional separation.
Data Source
AI summary
An improved technique provides scheduled data transfer between a mobile device and a server. The mobile device combines token codes generated by a soft token with sequences of auxiliary bits and displays the combinations to users as passcodes. Users may then copy the passcodes to their computers for authenticating to a server on a remote network. As the passcodes include both token codes and sequences of auxiliary bits, a communication channel is established whereby the auxiliary bits as well as the soft token codes are transmitted from the mobile device to the server.


