Stateless Security Device Authentication via Encrypted Challenge
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Highly secured devices, such as smart cards, lack stateful memory to track target devices securely, making them vulnerable to unauthorized access, and existing authentication methods are susceptible to malicious attacks.
Innovation Solution
A method for authenticating a security device that establishes a connection with a target device using a public value, sends an encrypted challenge, and requires a valid response within a threshold time to ensure only authorized access, without storing sensitive information on the security device, utilizing secure resources for encryption and decryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a trusted device stores authentication software and memory for authentication processes, then convenience is improved, but security is worsened due to vulnerability to malicious attacks
Solution Approach 1:
The patent extracts the authentication software and stateful memory from the trusted device, leaving only a secure element that stores private secrets. This separation removes the vulnerability points while preserving authentication functionality, as the secure element cannot be compromised even if the external trusted device is attacked.
Solution Approach 2:
The authentication system is segmented into two parts: a secure element that holds only private secrets without processing capability, and a trusted device that handles authentication software and state management. This segmentation ensures that the critical private secrets are isolated from potential attack vectors in the trusted device.
2Reliability
If a highly secured device lacks volatile storage, then security is improved, but functionality is worsened due to inability to track target devices
Solution Approach 1:
The patent introduces a trusted device as an intermediary that maintains the stateful memory and authentication software. The highly secured device (secure element) communicates with this intermediary, which handles the tracking of target devices and management of authentication states, allowing the secure element to remain stateless while maintaining full functionality.
3Adaptability or versatility
If sensitive information is stored on a security device, then authentication capability is improved, but security is worsened due to potential unauthorized access
Solution Approach 1:
The patent extracts sensitive information (private secrets) from the trusted device and stores it exclusively in a highly secured element that lacks volatile storage and processing capabilities. This extraction ensures that even if the trusted device is compromised, the private secrets remain protected, while the secure element can still perform authentication when properly triggered.
Data Source
AI summary
Some embodiments of the invention provide a method for authenticating a security device (e.g., a smart card or other highly secured device) to modify a security state (e.g., unlocking, decrypting, etc.) at a target device (e.g., laptop computers, mobile phones, tablets, etc.). In some embodiments, the security device does not have a volatile storage for storing volatile parameters for the particular device to use to perform the authentication process. The method of some embodiments sends an encrypted challenge to the security device, in which the encrypted challenge can only be decrypted by the security device. The method receives a response and modifies accessibility for the target device when the response is a valid response. The method of some embodiments determines that a response is valid based on the decrypted contents of the response and/or based on a period of time between the issuance of the challenge and the received response.


