Trusted Execution Environment for Single-Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication schemes are burdensome and unscalable, requiring users to manage multiple passwords and relying on hardware that is vulnerable to malware and credential-stealing attacks, making them impractical for modern computing needs.

Innovation Solution

A device authentication system using a trusted execution environment and secure element on a user device to establish secure communication sessions with external applications or devices, enabling users to authenticate via a single device with granular assurance levels (presence, intent, identification) and encrypting data to prevent credential theft.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional authentication schemes are used, then users can authenticate to multiple services, but users must memorize and manage multiple passwords which is burdensome

Engineering Contradiction:
Improveauthentication across multiple servicesVSAvoiduser burden of managing passwords
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements a universal authentication device that can authenticate users to multiple different services and devices using a single device. The system stores service-specific credentials and uses them to authenticate to various external applications and devices, eliminating the need for users to manage multiple passwords across different services.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication device acts as an intermediary between the user and multiple external services. It receives authentication requests from various services, presents appropriate challenges to the user through a unified interface, and automatically provides credentials to the requested service, thereby mediating the authentication process and reducing user burden.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If additional hardware is used for authentication, then security is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity against credential theftVSAvoidauthentication hardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple authentication functions into a single integrated device. The authentication device combines credential storage, cryptographic operations, user interface presentation, and communication protocols into one unified system, eliminating the need for separate hardware components for each authentication function and reducing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The single authentication device performs multiple functions including storing credentials for different services, generating authentication tokens, presenting user challenges, and communicating with various external devices. This multi-functional design provides strong security without requiring multiple specialized hardware devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If conventional authentication schemes are used, then authentication can be performed, but scalability is inhibited due to manual password management

Engineering Contradiction:
Improveauthentication functionalityVSAvoidscalability of authentication system
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authentication device automatically manages credentials for multiple services without requiring manual intervention. It stores service-specific credentials, automatically selects the appropriate credential set when receiving authentication requests, and handles the authentication process autonomously, enabling the system to scale to support numerous services without increasing user management overhead.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The authentication device is designed to support a large number of external services and devices through a unified architecture. It can store and manage credentials for multiple services simultaneously and present a consistent authentication interface regardless of the number or type of services, thereby enabling scalable authentication across diverse systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10182040B2Systems and methods for single device authentication
Publication Date: 2019.01.15 MASSACHUSETTS INST OF TECH
  • US10182040B2 patent drawing
  • US10182040B2 patent drawing
  • US10182040B2 patent drawing

AI summary

Described are systems, methods, and computer readable medium for authenticating user device interactions with external entities. A secure communication session is established between an external device or application and a trusted execution environment. An authentication request is received from the external application or device at the trusted execution environment. A secure communication channel is established between the trusted execution environment and an input/output interface of the user authentication device. Input is received from a user assurance action related to the authentication request over the secure communication channel. Data is encrypted at a secure element of the user authentication device, and a response is transmitted including the encrypted data and an indicator of the user assurance action to the external application or device from the trusted execution environment in response to the authentication request via the secure communication session.