Split Private Key Asymmetric Crypto System for Kiosk Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptosystems face challenges in providing secure access control, as they often rely on single factor authentication methods that are vulnerable to compromise and eavesdropping, and multifactor systems are costly and prone to dictionary attacks.
Innovation Solution
A method and system using a multifactor asymmetric crypto-key system with split private keys, where user authentication is based on different portions of the key, each requiring separate authentication factors, to provide varying levels of network access without exposing sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If single factor authentication (password) is used, then ease of operation is improved, but security is worsened due to vulnerability to compromise and eavesdropping
Solution Approach 1:
The private key is segmented into multiple portions, each protected by a different authentication factor. The authentication process is segmented into multiple stages where different factors are required for different levels of access. This segmentation allows the system to maintain ease of operation for basic access while providing enhanced security for sensitive operations.
Solution Approach 2:
The authentication system uses a composite approach combining multiple authentication factors (something you know, something you have, something you are) into a unified authentication framework. This composite structure provides graduated security levels while maintaining user-friendly operation for routine tasks.
2Reliability
If multifactor authentication systems are implemented, then security is improved, but device complexity and cost are worsened
Solution Approach 1:
The multifactor authentication system is segmented into modular components that can be independently implemented. Different authentication factors can be added or removed based on security requirements, allowing organizations to balance security needs against complexity and cost constraints.
Solution Approach 2:
The system implements partial multifactor authentication where not all factors are required for all operations. Different levels of authentication are applied based on the sensitivity of the resource being accessed, reducing overall complexity while maintaining security for critical functions.
3Ease of manufacture
If traditional password storage is used, then ease of manufacture is improved, but security is worsened due to single point of compromise
Solution Approach 1:
The authentication credentials are segmented across multiple secure storage locations including smart cards, tokens, and secure server storage. No single point contains all authentication factors, eliminating the single point of compromise while maintaining ease of system implementation through standardized security modules.
Data Source
AI summary
Techniques for providing different levels of access based upon a same authentication factor are provided. A first message is received that is transformed with a first portion of a split private key, the first portion based upon a user password and another factor, and the split private key associated with an asymmetric key pair having a public key and the split private key. The user is authenticated for a first level of network access based upon the received first message being transformed with the first portion. A second message is received that is transformed with a second portion of the split private key, the second portion based upon the password only and not combinable with the first portion to complete the split private key. The user is authenticated for a second level of network access different that the first level based upon the received second message being transformed with the second portion.


