One-Time Token Forward Clock Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing one-time authentication tokens are vulnerable to forward clock attacks, where an attacker manipulates the device time to obtain future passcodes, leading to synchronization issues and security breaches, as they rely on current time synchronization between the token and the server.
Innovation Solution
The method involves detecting forward clock attacks by comparing the current device time with the last used time, communicating an indication of the attack to the server through a separate channel, and suspending passcode generation, allowing the token to advance its time to prevent future passcode leakage and enabling server-side detection and prevention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the token relies on current time synchronization with the server, then passcode generation works normally, but the system becomes vulnerable to forward clock attacks where attackers can manipulate device time to obtain future passcodes
Solution Approach 1:
The patent applies preliminary action by detecting forward clock attacks before they can be exploited. The token compares the current device time with the last used time to identify time manipulations in advance, communicates attack indications to the server, and suspends passcode generation proactively to prevent future passcode leakage before attackers can obtain unauthorized access credentials
Solution Approach 2:
The patent implements feedback mechanisms where the token continuously monitors device time and compares it with the last used time, providing real-time feedback on time synchronization status. When a forward clock attack is detected, the system feeds back attack indication information to the server, enabling the server to update its state and prevent exploitation of the time manipulation
2Reliability
If the token suspends passcode generation upon detecting a forward clock attack, then security is improved, but the system becomes unusable until the future time point is reached
Solution Approach 1:
The patent applies parameter changes by modifying the token's operational state based on attack detection. When a forward clock attack is detected, the token changes its passcode generation parameters to suspend output, and the server changes its state to reflect the attack, allowing it to verify attack indication information and prevent unauthorized access while maintaining the ability to restore service
3Reliability
If the token communicates attack indication information to the server, then server-side prevention is enabled, but additional communication channels and processing are required
Solution Approach 1:
The patent uses the communication channel between token and server as an intermediary for attack prevention. The token communicates attack indication information to the server through existing communication infrastructure, and the server uses this information as a mediator to update its state and verify future passcode requests, enabling coordinated defense without requiring entirely new communication systems
Data Source
AI summary
Methods and apparatus are provided for improving resilience to forward clock attacks. A token generates a passcode from a user authentication token for presentation to an authentication server by detecting a forward clock attack; and communicating an indication of the forward clock attack to the authentication server. The generation of the user authentication passcodes is optionally suspended upon detecting the forward clock attack. The detection may be based on a comparison of a current device time of the token and a last used device time during a generation of a user authentication passcode.


