U2F Authentication via Digest File Generation on Portable Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users are deterred from utilizing authentication services based on the Universal 2nd Factor (U2F) protocol due to the additional cost of purchasing a physical key device specifically designed for it, which increases the cost of service usage.

Innovation Solution

An authentication system and method that utilizes an electronic device with a controller, processor, and key module, allowing users to generate and store digest files based on key factor information, enabling U2F authentication without the need for a specially designed physical key device by using existing portable storage or communication devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a physical key device specially designed for U2F protocol is used, then authentication security is improved, but user cost increases

Engineering Contradiction:
Improveauthentication securityVSAvoiduser cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent makes the electronic device itself perform U2F authentication functions by integrating the key generation and verification capabilities into the existing device hardware (controller, processor, storage), eliminating the need for a separate dedicated physical key device. The electronic device can generate key pairs, store private keys, and perform authentication operations directly.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines the functions of the separate physical key device with the existing electronic device components. The controller, processor, and storage units of the electronic device are merged to perform all U2F authentication operations that previously required a dedicated key device, reducing overall system complexity and cost.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If a dedicated physical key device is required, then authentication reliability is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The electronic device is designed to perform multiple functions including both general computing tasks and U2F authentication operations. The same processor, storage, and controller that handle normal device operations are also used for cryptographic key generation, storage, and authentication verification, eliminating the need for dedicated authentication hardware.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the authentication subsystem with the main device architecture. The controller, processor, and storage units are integrated to handle both regular device operations and U2F protocol operations, reducing the number of separate components and simplifying the overall system structure.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11509655B2Authentication system and authentication method
Publication Date: 2022.11.22 ITE TECH INC
  • US11509655B2 patent drawing
  • US11509655B2 patent drawing
  • US11509655B2 patent drawing

AI summary

An authentication system and an authentication method are provided. The electronic device of the authentication system includes a controller, a processor and a key module, wherein the processor performs an application program. In a binding phase, the application device generates a digest file according to key factor information and a selection strategy, and stores the digest file in a digest table of the electronic device. In a checking phase, the application program determines whether the controller corresponds to a binding device according to the digest file and the key factor information. If the controller corresponded to the binding device, in an authentication phase, the controller performs an authentication operation of a U2F service with a server device according to the digest file corresponding to the binding device in response to a pressing of the key module.