Output-Only Wireless Authentication Token Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional wireless authentication tokens are vulnerable to active attacks due to their ability to accept external input during authentication protocols, which compromises their security.
Innovation Solution
Implementing an output-only wireless authentication token that generates and transmits authentication information without external input, using techniques such as emulating standard wireless communication messages to transmit authentication information securely, and employing digital signatures to enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If wireless authentication tokens accept external input during authentication protocols, then ease of operation is improved, but security is worsened due to vulnerability to active attacks
Solution Approach 1:
The patent extracts the input acceptance functionality from the authentication token, creating an output-only device that generates and transmits authentication information without accepting external input during the authentication protocol, thereby eliminating the security vulnerability while maintaining operational simplicity
Solution Approach 2:
Instead of the conventional approach where tokens accept input and generate output, the patent inverts the model by creating a token that only outputs authentication information without accepting any input during authentication, fundamentally reversing the interaction model to achieve both simplicity and security
2Reliability
If digital signatures are employed to enhance security, then security is improved, but computation resources are worsened
Solution Approach 1:
The patent applies preliminary action by pre-computing and storing signature data in the authentication token before runtime, so that during authentication the token only needs to transmit pre-computed signature information rather than performing computationally intensive signature operations, thereby achieving strong security with minimal computational resource consumption
3Ease of operation
If emulating standard wireless communication messages is used to transmit authentication information, then ease of operation is improved, but device complexity is worsened
Solution Approach 1:
The patent uses copying by emulating standard wireless communication message formats (such as 802.11 beacon frames) to carry authentication information, allowing the token to transmit authenticated data using familiar, widely-supported protocols without requiring custom communication infrastructure, thereby achieving ease of operation while managing complexity through format replication
Data Source
AI summary
In one aspect, authentication information is received from a first processing device in a second processing device, and a digital signature is generated in the second processing device by signing data that incorporates at least a portion of the received authentication information. The received authentication information is generated at least in part from a secret seed stored in the first processing device. The received authentication information may be combined with the digital signature generated by the second processing device to form a joint signature that is transmitted to an authentication server. In an illustrative embodiment, the received authentication information comprises a tokencode and the digital signature is generated by signing data that incorporates the tokencode. The data that is signed to generate the digital signature may comprise an electronic document having the tokencode appended thereto.

