Hardware Token Binding via Host Fingerprint and Asymmetric Cryptography

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for managing hardware tokens in Public Key Infrastructure (PKI) centers are vulnerable to exploitation when tokens are used on unauthorized hosts, particularly over the internet, leading to security breaches and unauthorized access.

Innovation Solution

A system and method that binds a hardware token to a specific host device using fingerprint data and asymmetric cryptography, ensuring the token can only be used on the original host device unless explicitly permitted, thereby preventing unauthorized usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If hardware tokens are made accessible over the internet for remote access, then ease of operation is improved, but security vulnerability increases allowing exploitation on unauthorized hosts

Engineering Contradiction:
Improveremote token accessVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary binding of the hardware token to the host device before any cryptographic operations. The binding process captures host-specific fingerprint data and stores it in the token, creating a pre-established security association that prevents unauthorized use before exploitation can occur

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces fingerprint data as an intermediary binding element between the host and token. This intermediary serves as a mediator that verifies host identity through cryptographic comparison, allowing remote access while preventing unauthorized exploitation by ensuring only the bound host can successfully authenticate

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware tokens are bound to specific host devices using fingerprint data and asymmetric cryptography, then security is improved preventing unauthorized access, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidbinding mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security verification logic into a separate binding mechanism that operates independently. The fingerprint data and cryptographic operations are separated from the main token functionality, allowing the binding process to be implemented as a distinct module that enhances security without fundamentally redesigning the entire token system

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The binding mechanism uses universal cryptographic principles (asymmetric cryptography and fingerprint comparison) that can be applied across different hardware tokens and host devices. This multi-functional approach allows the same binding process to secure various token types without requiring device-specific customization, managing complexity through standardization

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If the token binding service stores encrypted fingerprint data and public keys remotely, then adaptability is improved allowing token migration, but loss of information increases risk of binding data compromise

Engineering Contradiction:
Improvetoken migration capabilityVSAvoidbinding data security
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The system implements local quality by storing sensitive binding data (encrypted fingerprint and public key) in a dedicated, secure location within the token rather than using general-purpose storage. This localized secure storage isolates critical binding information from other token data, reducing the risk of compromise while maintaining remote binding service capabilities

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11803631B2Binding a hardware security token to a host device to prevent exploitation by other host devices
Publication Date: 2023.10.31 ARRIS ENTERPRISES LLC
  • US11803631B2 patent drawing
  • US11803631B2 patent drawing
  • US11803631B2 patent drawing

AI summary

A system and method described below prevents exploitation of a client's PKI station using the a token installed on other host (attackers') processors. This is accomplished by binding the token to the approved PKI client station (host) using the a software development kit installed in the PKI client station. Once a token is bound to a PKI client station, the token can no longer be used on another station unless permitted by authorized personnel.