Soft Token Posture Assessment via Auxiliary Bits

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Soft tokens on mobile devices are vulnerable to security threats due to their complex functionality and multi-media communication capabilities, which existing adaptive authentication techniques struggle to effectively address when the device itself is the target of malicious activity.

Innovation Solution

Collecting device posture information, including software, hardware, and environmental context, and transmitting it to a server for assessment, where it is blended with token codes to create passcodes that are manually entered for authentication, allowing the server to authenticate users and assess device security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If soft tokens are installed on mobile devices with multiple communication media and software applications, then user convenience is improved, but security vulnerabilities increase

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authentication process into two distinct components: the soft token application that generates token codes, and the posture assessment system that evaluates device security status. This separation allows the token generation function to remain simple and user-friendly while the security assessment operates independently through background processes and sensor data collection, thus maintaining user convenience while addressing security vulnerabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces posture information and sensor data as intermediary elements between the user device and the authentication server. These intermediaries carry security status indicators (such as device posture, environmental context, and sensor readings) that provide the server with security assessment data without requiring direct exposure of the token generation process to potential attacks, thus bridging convenience and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If adaptive authentication techniques collect computer-specific information, then security is improved, but effectiveness decreases when the mobile device itself is attacked

Engineering Contradiction:
Improvesecurity detection effectivenessVSAvoidapplicability to mobile device attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of collecting detailed system information from the mobile device (which could expose security vulnerabilities), the patent inverts the approach by having the device report aggregated posture status and sensor data. This inversion protects the device's internal state while still providing the server with sufficient information to assess security risks associated with mobile device attacks.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent changes the parameters being collected from detailed system configurations and software states to high-level posture indicators and environmental sensor data. This parameter transformation maintains adaptability to mobile device attacks by capturing relevant security context (location, motion, ambient light) while avoiding exposure of sensitive device information that could be exploited.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If device posture information is continuously collected and transmitted, then security assessment is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoiddata collection and transmission complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements periodic posture assessment and selective transmission of security information rather than continuous monitoring and transmission. The soft token application periodically evaluates device posture and only transmits data when security-relevant changes are detected or at scheduled intervals, thereby maintaining accurate security assessment while minimizing the complexity burden on the mobile device.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent applies partial action by collecting and transmitting only the subset of posture information that is most relevant to security assessment, rather than continuously monitoring and transmitting all possible device parameters. This selective approach maintains security assessment accuracy while reducing computational and communication overhead on the mobile device.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8683563B1Soft token posture assessment
Publication Date: 2014.03.25 RSA SECURITY USA LLC
  • US8683563B1 patent drawing
  • US8683563B1 patent drawing
  • US8683563B1 patent drawing

AI summary

An improved technique for assessing the security status of a device on which a soft token is run collects device posture information from the device running the soft token and initiates transmission of the device posture information to a server to be used in assessing whether the device has been subjected to malicious activity. The device posture information may relate to the software status, hardware status, and/or environmental context of the device. In some examples, the device posture information is transmitted to the server directly. In other examples, the device posture information is transmitted to the server via auxiliary bits embedded in passcodes displayed to the user, which the user may read and transfer to the server as part of authentication requests. The server may apply the device posture information in a number of areas, including, for example, authentication management, risk assessment, and/or security analytics.