Terminal-Based Application Secret Reset Using Secure Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for resetting application secrets, such as passwords, are inadequate due to ease of use and security concerns, particularly with solutions like email addresses and recovery keys.
Innovation Solution
A method for resetting application secrets using a reset element stored in the terminal's secure environment, requiring user authentication and employing cryptographic processing with encryption keys, either symmetric or asymmetric, and optionally external authentication factors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If external proof factors (email, phone, recovery key) are used for secret reset, then the secret can be reset, but security is compromised or usability deteriorates
Solution Approach 1:
The invention extracts the reset functionality from external systems (email servers, phone networks) and brings it into the terminal's secure environment. The reset element is stored locally in a secure element or trusted execution environment, eliminating dependency on external proof factors and their associated security risks while maintaining ease of use through local authentication.
Solution Approach 2:
The secure environment acts as an intermediary between the user and the application secret reset process. Instead of directly using external factors like email or phone, the user authenticates through the secure environment which then mediates the reset operation, providing both security and usability benefits.
2Reliability
If complex recovery keys are stored for secret reset, then security is improved, but ease of use deteriorates due to storage and availability requirements
Solution Approach 1:
The secure environment provides self-service authentication capabilities using biometric data or device-locked credentials that are already stored in the terminal. Users authenticate themselves through the secure environment without needing to manually store or retrieve complex recovery keys, as the system automatically manages the authentication process using pre-stored biometric templates or device credentials.
3Ease of operation
If email address is used as proof factor, then secret reset is enabled, but security deteriorates due to synchronization on terminal
Solution Approach 1:
The invention removes the email address dependency from the reset process entirely. Instead of using email as a proof factor, the reset element is extracted and stored in the terminal's secure environment, eliminating the security vulnerability of email synchronization while maintaining ease of use through local authentication mechanisms.
Data Source
AI summary
A method for reinitializing an application secret of an application executed by a terminal, the terminal including a security infrastructure to securely manage data for authenticating a user by the terminal. The application is connected to an application server. The method includes, after the user requests reinitialization of the application secret from the application, the security infrastructure receiving a request to cryptographically process a verification element by using an element for reinitializing the application secret stored beforehand in the security infrastructure; authenticating the user based on data entered by the user and authentication data stored in the security infrastructure; and if the user is authenticated; cryptographically processing the element for verifying the application secret to obtain an element for validating the reinitialization, which is sent to the application so that the application server validates the element and, if applicable, executes a process of reinitializing the application secret.


