Trusted Device Authentication Tunneling Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face security vulnerabilities when remotely logging into secure servers from distrusted client devices, as their login credentials can be intercepted or leaked due to malware, phishing, or sniffing attacks, and existing protection methods can be circumvented.

Innovation Solution

Establishing a first secure connection between the client and server, followed by a second secure connection tunneled within the first, using a trusted device to authenticate and communicate credentials, thereby protecting credentials from display on the distrusted client and preventing leakage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a user enters login credentials on a distrusted client device, then the login process can be completed, but the credentials may be intercepted or leaked due to malware, phishing, or sniffing attacks

Engineering Contradiction:
Improvelogin processVSAvoidcredential interception
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trusted device as an intermediary between the client and server. The client device communicates credentials to the trusted device, which then forwards them to the server. This intermediary prevents direct exposure of credentials on the distrusted client device, protecting against malware, phishing, and sniffing attacks while maintaining ease of login operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If credentials are displayed on the client device for user input, then ease of operation is improved, but security is worsened as credentials can be displayed in plaintext to malware

Engineering Contradiction:
Improvecredential inputVSAvoidcredential security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The trusted device serves as a secure intermediary that receives credentials from the client device and transmits them to the server without displaying credentials in plaintext on the client device. This maintains ease of operation for credential input while ensuring security by preventing plaintext display to malware.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the traditional mechanical display-input system with a secure communication channel through the trusted device. Instead of displaying credentials on the client device screen, the system uses encrypted communication through the trusted device to transmit credentials, substituting the visual display mechanism with a secure transmission mechanism.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If a specialized tamper-resistant token device is used for authentication, then security is improved, but device complexity and cost increase

Engineering Contradiction:
Improveauthentication securityVSAvoidtoken device
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the trusted device universal by allowing any device the user trusts to serve as the authentication intermediary. Instead of requiring a specialized tamper-resistant token device, the system accepts any device the user controls and trusts, such as a smartphone or computer, thereby reducing device complexity and cost while maintaining high authentication security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent replaces expensive specialized token devices with any device the user already possesses and trusts. This approach uses the user's existing devices (which may be less expensive and more flexible) as the authentication intermediary, reducing the need for specialized hardware while maintaining security through the user's trust in the device.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS8214890B2Login authentication using a trusted device
Publication Date: 2012.07.03 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8214890B2 patent drawing
  • US8214890B2 patent drawing
  • US8214890B2 patent drawing

AI summary

A user working on a client computer is allowed to remotely login to a server over a computer network. A first secure connection is established between the client and the server. Communications with a trusted device which is in the user's control is established via a communication channel between the trusted device and the client, where this channel is not part of the network. A second secure connection is established between the trusted device and the server through the client, where this second secure connection is tunneled within the first secure connection. The user remotely logs into the server over the second secure connection using the trusted device.