Storage Device as Hardware Token for Multi-Factor Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access management systems lack a customizable and transferable solution for multi-factor authentication, limiting their use across different applications and users, and often require credential information for authentication, which can be insecure.

Innovation Solution

A data storage device is configured as a security device to operate as a hardware-based token for multi-factor authentication, allowing users to manage and recreate security data, ensuring secure access without credential input and preventing unauthorized use by being specific to each device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access management systems are used, then authentication can be performed, but they require credential information which can be compromised and are not customizable for different users and applications

Engineering Contradiction:
Improveauthentication securityVSAvoidcustomizability for different users and applications
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments authentication into multiple independent factors (something you know, something you have, something you are) that can be independently configured and combined. Each factor is handled by separate modules that can be customized for different users and applications, allowing flexible authentication policies without compromising security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication system dynamically adapts by selecting and combining different authentication factors based on user roles, application requirements, and security policies. The system can change authentication requirements in real-time rather than using fixed credential verification, enabling customization across different users and applications while maintaining reliability.

Inventive Principle:
Principle #15Dynamics

2Reliability

If multi-factor authentication is implemented, then security is improved, but the system becomes complex and not transferable between devices

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal authentication framework that can operate across multiple devices and platforms. The system uses standardized interfaces and protocols that allow the same multi-factor authentication mechanism to function on different device types without requiring device-specific implementations, reducing complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary authentication service that manages the complexity of multi-factor authentication centrally. This intermediary handles the coordination between different authentication factors, devices, and applications, shielding users from complexity while enabling transferability across devices through standardized communication protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If dedicated security devices are used, then authentication is secure, but users cannot recreate security data if devices are lost or damaged

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice transferability and recovery
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables recovery of authentication capability by allowing users to re-register and recreate security data on replacement devices. The authentication framework stores verification data in a way that can be重新established through the registration process, ensuring that lost or damaged devices can be replaced without permanent loss of access while maintaining security through the multi-factor approach.

Inventive Principle:
Principle #34Discarding and recovering

Solution Approach 2:

The system performs preliminary registration and setup of authentication factors before actual use. During registration, the system pre-configures multiple authentication factors and stores verification data securely. This preliminary action ensures that if a device is lost, the user can recover by going through the registration process again, as the framework is already prepared to verify and establish authentication capability on new devices.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10462142B2Techniques for implementing a data storage device as a security device for managing access to resources
Publication Date: 2019.10.29 ORACLE INT CORP
  • US10462142B2 patent drawing
  • US10462142B2 patent drawing
  • US10462142B2 patent drawing

AI summary

Techniques are disclosed for implementation of a data storage device as a security device for managing access to resources. These techniques can be implemented for multi-factor authentication (MFA) to provide multiple layers of security for managing access to resources in an enterprise and/or a cloud computing environments. As a security device, a storage device can be used a portable device to provide a point of trust for multi-factor authentication across any client application or device operated to access resources. A storage device may be configured with security data for authentication with an access management system. After configuration, a portable storage device may be used for authentication of a user without credential information at any client device based on accessibility of the device to the portable storage device. A storage device configured as a security device can ensure that legitimate users have an easy way to authenticate and access the resources.