Authentication Token Attestation Module for APT Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication methods, despite using one-time passcode tokens and two-factor authentication, are vulnerable to advanced persistent threats (APTs) due to increasing sophistication of attackers, necessitating enhanced security measures for protecting sensitive resources.

Innovation Solution

Authentication tokens are equipped with an attestation module that consumes and verifies platform attestations from clients before releasing authentication information, ensuring that only valid attestations lead to the release of authentication data, thereby enhancing security against APTs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication tokens are used with two-factor authentication, then basic security protection is provided, but the system remains vulnerable to advanced persistent threats (APTs)

Engineering Contradiction:
Improvesecurity protectionVSAvoidvulnerability to APTs
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification of client platform integrity through attestation before releasing authentication information. The token checks whether the client's software stack and hardware platform meet predetermined security policies in advance, preventing authentication information from being released to potentially compromised systems. This preliminary action blocks APTs before they can exploit authentication mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an attestation module as an intermediary between the authentication token and the client system. This intermediary verifies platform integrity through cryptographic attestations about the client's software stack and hardware configuration. The attestation module acts as a security gatekeeper, mediating whether authentication information should be released based on platform trustworthiness, thereby protecting against APTs without changing core authentication functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication information is released based on client attestation, then security against APTs is enhanced, but device complexity increases

Engineering Contradiction:
Improveprotection against APTsVSAvoidtoken structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The attestation module within the authentication token is designed to perform multiple functions: it generates authentication information, verifies client platform attestations, evaluates policy compliance, and controls release of authentication data. By consolidating these security functions into a single multi-functional module rather than separate systems, the patent enhances protection against APTs while minimizing the increase in overall device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9659177B1Authentication token with controlled release of authentication information based on client attestation
Publication Date: 2017.05.23 EMC IP HLDG CO LLC
  • US9659177B1 patent drawing
  • US9659177B1 patent drawing
  • US9659177B1 patent drawing

AI summary

An authentication token configured to generate authentication information comprises an attestation module. The attestation module of the authentication token is configured to receive an attestation generated by an attestation module of a client, to perform a check on the received attestation, and to release the authentication information to a designated entity if the check indicates that the attestation is valid. The designated entity may comprise the client itself or another entity that participates in an authentication process involving at least one of the authentication token and the client. The authentication token in performing the check on the attestation received from the client may determine if the received attestation conforms to a predetermined policy. The attestation may comprise a platform attestation generated by the client for a given instantiated software stack of the client.