One-Time Token Forward Clock Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing one-time authentication tokens are vulnerable to forward clock attacks, where an attacker manipulates the device time to obtain future passcodes, leading to synchronization issues and security breaches, as they rely on current time synchronization between the token and the server.

Innovation Solution

The method involves detecting forward clock attacks by comparing the current device time with the last used time, communicating an indication of the attack to the server through a separate channel, and suspending passcode generation, allowing the token to advance its time to prevent future passcode leakage and enabling server-side detection and prevention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the token relies on current time synchronization with the server, then passcode generation works normally, but the system becomes vulnerable to forward clock attacks where attackers can manipulate device time to obtain future passcodes

Engineering Contradiction:
ImprovesecurityVSAvoidforward clock attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by detecting forward clock attacks before they can be exploited. The token compares the current device time with the last used time to identify time manipulations in advance, communicates attack indications to the server, and suspends passcode generation proactively to prevent future passcode leakage before attackers can obtain unauthorized access credentials

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the token continuously monitors device time and compares it with the last used time, providing real-time feedback on time synchronization status. When a forward clock attack is detected, the system feeds back attack indication information to the server, enabling the server to update its state and prevent exploitation of the time manipulation

Inventive Principle:
Principle #23Feedback

2Reliability

If the token suspends passcode generation upon detecting a forward clock attack, then security is improved, but the system becomes unusable until the future time point is reached

Engineering Contradiction:
ImprovesecurityVSAvoidsystem usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies parameter changes by modifying the token's operational state based on attack detection. When a forward clock attack is detected, the token changes its passcode generation parameters to suspend output, and the server changes its state to reflect the attack, allowing it to verify attack indication information and prevent unauthorized access while maintaining the ability to restore service

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the token communicates attack indication information to the server, then server-side prevention is enabled, but additional communication channels and processing are required

Engineering Contradiction:
Improveattack preventionVSAvoidcommunication infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses the communication channel between token and server as an intermediary for attack prevention. The token communicates attack indication information to the server through existing communication infrastructure, and the server uses this information as a mediator to update its state and verify future passcode requests, enabling coordinated defense without requiring entirely new communication systems

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9654467B1Time synchronization solutions for forward-secure one-time authentication tokens
Publication Date: 2017.05.16 EMC IP HLDG CO LLC
  • US9654467B1 patent drawing
  • US9654467B1 patent drawing
  • US9654467B1 patent drawing

AI summary

Methods and apparatus are provided for improving resilience to forward clock attacks. A token generates a passcode from a user authentication token for presentation to an authentication server by detecting a forward clock attack; and communicating an indication of the forward clock attack to the authentication server. The generation of the user authentication passcodes is optionally suspended upon detecting the forward clock attack. The detection may be based on a comparison of a current device time of the token and a last used device time during a generation of a user authentication passcode.