USB Authentication Token for Secure Remote Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems for remote access to computer systems are vulnerable to security breaches due to the use of logical security elements that can be detected by keystroke loggers or observed, necessitating the integration of physical security elements like smartcards and USB flash memories for enhanced security.

Innovation Solution

A method and system for establishing a secure connection between electronic devices using a USB stick with memory for user identification and an initialization module, which initializes and manages the secure connection over an insecure communication network, integrating physical and logical authentication mechanisms for secure data exchange and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If logical security elements like PIN are used for authentication, then ease of operation is improved, but security is worsened because they can be detected by keystroke loggers or observed

Engineering Contradiction:
Improveauthentication convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent combines logical security elements (PIN code) with physical security elements (USB flash memory device) into a unified authentication system. The USB device stores authentication credentials and communicates with the terminal device, creating a merged security mechanism that requires both physical possession of the device and knowledge of the PIN code, thereby maintaining operational convenience while significantly enhancing security against keystroke loggers and observation attacks

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The USB flash memory device acts as an intermediary between the user and the terminal device during authentication. Instead of directly entering the PIN code into the terminal, the user interacts with the USB device which then mediates the authentication process by providing credentials to the terminal, thereby protecting the PIN from direct exposure to potentially compromised terminal input mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If physical security elements like smartcards are used for authentication, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The USB flash memory device serves multiple functions: it acts as a security credential storage device, an authentication token, and a communication interface between the user and terminal device. This multi-functional design eliminates the need for separate smartcard readers, card slots, and associated software, thereby maintaining high security while reducing overall system complexity compared to dedicated smartcard infrastructure

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses a USB flash memory device as a portable copy or alternative representation of traditional smartcard functionality. Instead of requiring users to carry and insert physical smartcards into dedicated readers, the authentication credentials are copied onto a ubiquitous USB device that can be easily connected to various terminals, simplifying the physical infrastructure requirements while maintaining security

Inventive Principle:
Principle #26Copying

3Reliability

If multiple security elements are combined for authentication, then security is improved, but ease of operation is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The USB flash memory device performs self-service functions by automatically providing authentication credentials to the terminal device when connected. The device manages its own communication protocols, credential encryption, and authentication sequences without requiring user intervention beyond the simple action of connecting the USB device and entering the PIN code, thereby maintaining ease of operation while implementing multiple security layers

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9432333B2Trusted content distribution system
Publication Date: 2016.08.30 E BO ENTERPRISES
  • US9432333B2 patent drawing
  • US9432333B2 patent drawing
  • US9432333B2 patent drawing

AI summary

A trusted content distribution system is described comprising a trustworthy enduser device and a network management infrastructure, the enduser device being adapted for communications between the enduser device and the networked infrastructure via a secure tunnel; the end user device comprising a host processor and memory; secure non-volatile memory for storing an operating system, a trusted boot process executed by the host processor to boot the end user device into a known state, means for communicating with a visualization device.