Output-Only Wireless Authentication Token Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional wireless authentication tokens are vulnerable to active attacks due to their ability to accept external input during authentication protocols, which compromises their security.

Innovation Solution

Implementing an output-only wireless authentication token that generates and transmits authentication information without external input, using techniques such as emulating standard wireless communication messages to transmit authentication information securely, and employing digital signatures to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless authentication tokens accept external input during authentication protocols, then ease of operation is improved, but security is worsened due to vulnerability to active attacks

Engineering Contradiction:
Improveauthentication operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the input acceptance functionality from the authentication token, creating an output-only device that generates and transmits authentication information without accepting external input during the authentication protocol, thereby eliminating the security vulnerability while maintaining operational simplicity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of the conventional approach where tokens accept input and generate output, the patent inverts the model by creating a token that only outputs authentication information without accepting any input during authentication, fundamentally reversing the interaction model to achieve both simplicity and security

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If digital signatures are employed to enhance security, then security is improved, but computation resources are worsened

Engineering Contradiction:
ImprovesecurityVSAvoidcomputation resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies preliminary action by pre-computing and storing signature data in the authentication token before runtime, so that during authentication the token only needs to transmit pre-computed signature information rather than performing computationally intensive signature operations, thereby achieving strong security with minimal computational resource consumption

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If emulating standard wireless communication messages is used to transmit authentication information, then ease of operation is improved, but device complexity is worsened

Engineering Contradiction:
Improveauthentication operationVSAvoidcommunication protocol
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent uses copying by emulating standard wireless communication message formats (such as 802.11 beacon frames) to carry authentication information, allowing the token to transmit authenticated data using familiar, widely-supported protocols without requiring custom communication infrastructure, thereby achieving ease of operation while managing complexity through format replication

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11973862B2Authentication methods and apparatus for generating digital signatures
Publication Date: 2024.04.30 EMC IP HLDG CO LLC
  • US11973862B2 patent drawing
  • US11973862B2 patent drawing

AI summary

In one aspect, authentication information is received from a first processing device in a second processing device, and a digital signature is generated in the second processing device by signing data that incorporates at least a portion of the received authentication information. The received authentication information is generated at least in part from a secret seed stored in the first processing device. The received authentication information may be combined with the digital signature generated by the second processing device to form a joint signature that is transmitted to an authentication server. In an illustrative embodiment, the received authentication information comprises a tokencode and the digital signature is generated by signing data that incorporates the tokencode. The data that is signed to generate the digital signature may comprise an electronic document having the tokencode appended thereto.