Remote Token Password Reset via Third-Party Credential
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional password reset mechanisms for tokens, such as smart cards, are cumbersome and insecure, especially in large systems where a single security officer password is shared across multiple tokens, leading to scalability issues and increased security risks if compromised.
Innovation Solution
A remote password reset method using a third-party authentication credential, such as a social security number or secret question, is implemented, allowing for secure communication between a security server and the token to update the password after mutual authentication, reducing the burden on token management systems and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a security officer is provided with a global password to unlock smart cards, then password reset capability is achieved, but security risk increases and scalability is limited
Solution Approach 1:
The patent segments the security architecture by separating token management functions between the security officer and the token management system. The TMS maintains a database of token identifiers and associated passwords, allowing the security officer to request password resets for specific tokens without possessing global access credentials. This segmentation eliminates the security risk of global passwords while maintaining password reset capability.
Solution Approach 2:
The token management system acts as an intermediary between the security officer and the tokens. When a security officer needs to reset a password, they submit a request through the TMS, which then communicates with the token to establish a secure communication channel and reset the password. This intermediary approach eliminates the need for security officers to have direct global access to all tokens.
2Ease of operation
If a security officer is provided with a global password to unlock smart cards, then password reset capability is achieved, but system scalability is reduced
Solution Approach 1:
The token management system provides universal functionality for managing multiple tokens across the organization. It maintains a centralized database that can store and manage credentials for any number of tokens, allowing the system to scale from small to large deployments without requiring changes to the password reset process. The TMS can handle requests for any token in its database, making the system adaptable to growing organizational needs.
3Reliability
If security officer passwords are managed on a per token basis, then security risk is reduced, but management complexity increases
Solution Approach 1:
The token management system provides self-service functionality by automatically managing the complexity of per-token credential management. When a security officer requests a password reset, the TMS handles the entire process including validating the token identifier, establishing secure communication channels, and resetting the password without requiring the security officer to manually manage individual token credentials. This automation eliminates the management burden while maintaining enhanced security.
4Reliability
If a list of security officer passwords for each token is maintained, then per-token security is achieved, but maintenance burden increases
Solution Approach 1:
The patent replaces the mechanical approach of manually maintaining lists of per-token passwords with an automated electronic system. The token management system stores token identifiers and associated passwords in a database, and automatically retrieves and applies the correct credentials when processing password reset requests. This substitution eliminates the time-consuming manual maintenance of credential lists while maintaining per-token security through automated, accurate credential management.
Data Source
AI summary
Embodiments of the present invention provide a secure remote password reset capability. In some embodiments, an exemplary method provides a remote reset of a password associated with a token in a computer system having a security server. A token-based authentication process is activated by connecting the token to the security server. A server-based authentication process is initiated in the security server by activating a password reset process in a security client. The server-based authentication process communicates with the token-based authentication process over a secure channel. An authentication credential is managed by a third party agent that supplies a query and the authentication credential as a correct response to the query to the security server. A prompt provided by the password reset process collects the authentication credential and a new password. After the authentication credential is validated mutually authentication is performed between the security server and the token. The token is updated with the new password based on a successful result of the mutual authentication.


