Soft Token Reverse Channel for Dynamic Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication systems restrict soft tokens from accepting input from the authentication server once they are activated and start producing one-time passwords (OTPs), limiting the ability to dynamically adjust operations or enhance security post-deployment.
Innovation Solution
Implementing a reverse channel for communication from the authentication server to the soft token, allowing the server to modify the soft token's operation, such as changing its hardware fingerprint, software posture, or re-seeding it, to dynamically strengthen authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the soft token is prevented from accepting input after activation to ensure tamper resistance, then security against tampering is improved, but the ability to dynamically adjust operations or enhance security post-deployment deteriorates
Solution Approach 1:
The patent inverts the conventional unidirectional communication model by implementing a reverse channel that allows the authentication server to send commands back to the soft token. This enables dynamic reconfiguration of the token's machine states (such as re-seeding cryptographic keys or adjusting operational parameters) while maintaining tamper resistance through the secure reverse channel protocol
2Reliability
If the soft token is configured to stop operation upon detecting tampering, then security against unauthorized access is improved, but the operational continuity and availability deteriorate
Solution Approach 1:
The patent implements a feedback mechanism where the authentication server receives status information from the soft token and can respond by sending modify commands through the reverse channel. This allows the server to verify token integrity, detect tampering attempts, and respond appropriately by either reconfiguring the token or stopping operation based on the detected threat level, thereby balancing security with operational continuity
Data Source
AI summary
A technique controls a soft token running within an electronic apparatus. The technique involves providing an initial series of authentication codes based on a first set of machine states. The initial series of authentication codes is provided from the electronic apparatus to a server through a forward channel to authenticate a user. The technique further involves receiving a command from the server through a reverse channel between the electronic apparatus and the server. The reverse channel provides communications in a direction opposite to that of the forward channel. The technique further involves changing the first set of machine states to a second set of machine states in response to the command, and providing a new series of authentication codes based on the second set of machine states. The new series of authentication codes is provided from the electronic apparatus to the server through the forward channel for user authentication.


