USB Authentication Device Using Unique Key Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems for devices, especially those not network-connected, lack the ability to implement fine control over access to restricted modes of operation and cannot convert standard USB mass storage devices into secure authentication keys.
Innovation Solution
A method and system that utilize a USB device's unique identification characteristics, such as vendor ID, product ID, and serial number, to generate a unique key file, which is then stored on the USB device, enabling it to function as a secure authentication device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If usernames and passwords are used for authentication, then access control to restricted modes is achieved, but the system becomes vulnerable to password loss, forgotten credentials, and discovery by unauthorized parties
Solution Approach 1:
The patent replaces the mechanical/password-based authentication system with a cryptographic key-based system. Instead of relying on usernames and passwords that can be forgotten or discovered, the system uses unique cryptographic keys generated from USB device identification characteristics. This substitution eliminates the vulnerability associated with password management while maintaining access control functionality.
Solution Approach 2:
The patent introduces a key generation server as an intermediary between the USB device and the authentication process. This intermediary generates unique keys based on USB identification characteristics and distributes them securely. The intermediary approach centralizes key management and eliminates the need for users to remember or secure their own credentials, thereby improving reliability while reducing security vulnerabilities.
2Reliability
If custom authentication tokens or fobs are used, then secure authentication is achieved, but the system complexity increases and specific components must be provisioned for each user
Solution Approach 1:
The patent applies universality by using standard USB mass storage devices as the authentication carrier instead of requiring custom tokens or fobs. The USB device's inherent identification characteristics (vendor ID, product ID, serial number) are used to generate unique authentication keys. This approach maintains security while eliminating the need for specialized authentication hardware, thereby reducing system complexity.
Solution Approach 2:
The patent uses the USB device's existing identification characteristics as a template to generate cryptographic keys. Instead of requiring unique physical tokens for each user, the system copies and extends the USB device's inherent identifiers into the cryptographic domain. This copying approach maintains security while leveraging already-available components, reducing overall system complexity.
3Extent of automation
If network connection is required for authentication, then centralized key management is achieved, but devices cannot be authenticated when offline
Solution Approach 1:
The patent applies preliminary action by pre-generating and storing unique authentication keys on USB devices before they are needed for authentication. The key generation server creates keys in advance and distributes them to users who then store them on their USB devices. This preliminary preparation enables offline authentication capability while maintaining the benefits of centralized key management during the provisioning phase.
Data Source
AI summary
The disclosure relates to systems, devices, and methods for authenticating users of any device requiring authentication, such as a medical device. The systems, devices, and methods can convert a standard USB mass storage device into a unique USB based authentication device that authenticates a user. The device can be programmed to grant access to one or more functions only upon verification of a user by inserting the USB based authentication device into the medical device.


