Trusted Device Authentication Tunneling Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face security vulnerabilities when remotely logging into secure servers from distrusted client devices, as their login credentials can be intercepted or leaked due to malware, phishing, or sniffing attacks, and existing protection methods can be circumvented.
Innovation Solution
Establishing a first secure connection between the client and server, followed by a second secure connection tunneled within the first, using a trusted device to authenticate and communicate credentials, thereby protecting credentials from display on the distrusted client and preventing leakage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a user enters login credentials on a distrusted client device, then the login process can be completed, but the credentials may be intercepted or leaked due to malware, phishing, or sniffing attacks
Solution Approach 1:
The patent introduces a trusted device as an intermediary between the client and server. The client device communicates credentials to the trusted device, which then forwards them to the server. This intermediary prevents direct exposure of credentials on the distrusted client device, protecting against malware, phishing, and sniffing attacks while maintaining ease of login operation.
2Ease of operation
If credentials are displayed on the client device for user input, then ease of operation is improved, but security is worsened as credentials can be displayed in plaintext to malware
Solution Approach 1:
The trusted device serves as a secure intermediary that receives credentials from the client device and transmits them to the server without displaying credentials in plaintext on the client device. This maintains ease of operation for credential input while ensuring security by preventing plaintext display to malware.
Solution Approach 2:
The patent replaces the traditional mechanical display-input system with a secure communication channel through the trusted device. Instead of displaying credentials on the client device screen, the system uses encrypted communication through the trusted device to transmit credentials, substituting the visual display mechanism with a secure transmission mechanism.
3Reliability
If a specialized tamper-resistant token device is used for authentication, then security is improved, but device complexity and cost increase
Solution Approach 1:
The patent makes the trusted device universal by allowing any device the user trusts to serve as the authentication intermediary. Instead of requiring a specialized tamper-resistant token device, the system accepts any device the user controls and trusts, such as a smartphone or computer, thereby reducing device complexity and cost while maintaining high authentication security.
Solution Approach 2:
The patent replaces expensive specialized token devices with any device the user already possesses and trusts. This approach uses the user's existing devices (which may be less expensive and more flexible) as the authentication intermediary, reducing the need for specialized hardware while maintaining security through the user's trust in the device.
Data Source
AI summary
A user working on a client computer is allowed to remotely login to a server over a computer network. A first secure connection is established between the client and the server. Communications with a trusted device which is in the user's control is established via a communication channel between the trusted device and the client, where this channel is not part of the network. A second secure connection is established between the trusted device and the server through the client, where this second secure connection is tunneled within the first secure connection. The user remotely logs into the server over the second secure connection using the trusted device.


