Trusted Computing Environment for Secure Token Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure token manufacturing processes require central encryption authority involvement, limiting outsourcing to untrusted third-party manufacturers due to insecurity and validation challenges, as they cannot verify token codes without knowing the seed.

Innovation Solution

A system where untrusted third-party manufacturers are provided with a trusted computing environment to validate token codes without disclosing the seed, using tamper-resistant chips with unique codes and a secret algorithm to ensure security, allowing token configuration and validation without knowledge of the seed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If the seed is programmed into the token at the time of manufacture by an untrusted third-party manufacturer, then manufacturing costs are reduced through outsourcing, but the seed becomes insecure and the manufacturer can validate token codes

Engineering Contradiction:
Improvemanufacturing costVSAvoidseed security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

A trusted computing environment (TCE) acts as an intermediary between the untrusted manufacturer and the seed. The TCE is a secure platform provided by the token manufacturer that allows the central encryption authority to program the seed without exposing it to the untrusted third-party manufacturer. The TCE ensures that the seed remains secure while still allowing the manufacturer to validate token codes through controlled interactions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the manufacturer is given the secret algorithm and cryptographic key to validate token codes, then validation capability is achieved, but the security benefits of the technique are reduced or eliminated

Engineering Contradiction:
Improvetoken code validationVSAvoidseed security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The validation process is segmented into two distinct phases: programming phase and validation phase. During programming, the TCE programs the seed into the token without exposing it to the manufacturer. During validation, the manufacturer uses the TCE to verify token codes without needing to know the seed or have access to the secret algorithm and key. This segmentation allows validation capability while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trusted computing environment serves as an intermediary that enables token code validation without requiring the manufacturer to possess the seed or secret keys. The TCE performs the cryptographic validation operations securely, allowing the manufacturer to verify token codes while the seed remains protected from exposure to the untrusted manufacturer.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a trusted computing environment is provided to the manufacturer, then secure seed programming and validation are achieved, but device complexity increases

Engineering Contradiction:
Improveseed securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted computing environment is self-contained and self-managing. It automatically handles seed programming, token code generation, and validation operations without requiring complex external systems. The TCE manages its own cryptographic operations and provides secure interfaces for both the central encryption authority and the manufacturer, reducing the complexity burden on the overall system architecture.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8307210B1Method and apparatus for secure validation of tokens
Publication Date: 2012.11.06 RSA SECURITY INC
  • US8307210B1 patent drawing
  • US8307210B1 patent drawing
  • US8307210B1 patent drawing

AI summary

A method for validating a cryptographic token includes (a) operating the cryptographic token to generate a pseudo-random number for authentication purposes by using a cryptographic seed uniquely associated with the cryptographic token, the cryptographic seed having been cryptographically generated using a precursor value, (b) receiving a first value from the cryptographic token, the first value being the pseudo-random number generated by the cryptographic token, (c) inputting the first value and the precursor value into a trusted computing platform, and (d) operating the trusted computing platform to generate a validation signal if the first value can be derived using a specified algorithm from the precursor value, but to generate a failure signal if the first value cannot be derived using the specified algorithm from the precursor value. Accompanying methods and apparatus are also provided.