Authentication Server Key Exchange for Secure Messaging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Electronic messages transmitted over networks, such as SMS or email, are vulnerable to security risks, exposing sensitive information due to lack of effective encryption and authentication mechanisms.

Innovation Solution

A system and method that uses authentication servers to securely exchange parameters between user devices for generating encryption and decryption keys, employing multiple layers of authentication, such as the Generic Bootstrapping Architecture (GBA) process, to ensure secure message transmission and reception without exchanging the keys themselves.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If electronic messages are transmitted over networks without encryption, then ease of operation is improved, but security and reliability deteriorate

Engineering Contradiction:
Improveease of message transmissionVSAvoidmessage security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces authentication servers as intermediaries that facilitate secure key exchange between user devices. These servers act as trusted mediators that enable encryption without requiring direct key sharing between communicating parties, thus maintaining ease of operation while improving security through server-mediated authentication and key distribution

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If encryption keys are exchanged directly between user devices, then device complexity is reduced, but security deteriorates due to exposure during transmission

Engineering Contradiction:
Improvecomplexity of encryption systemVSAvoidkey exchange security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The authentication servers serve as intermediaries that handle the sensitive key exchange process. Instead of devices directly exchanging encryption keys, they communicate through the authenticated server infrastructure, which verifies identities and securely distributes keys. This eliminates direct key exposure between devices while maintaining manageable system complexity through standardized protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service authentication where user devices automatically perform authentication and key acquisition through the authentication servers without manual intervention. The devices autonomously obtain encryption keys through authenticated sessions, eliminating the need for manual key distribution while ensuring security through automated authentication protocols

Inventive Principle:
Principle #25Self-service

3Reliability

If multiple layers of authentication are implemented, then reliability and security are improved, but device complexity and processing time increase

Engineering Contradiction:
Improveauthentication securityVSAvoidcomplexity of authentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into distinct functional components: user device authentication, server authentication, and key generation stages. Each authentication layer operates as an independent module with specific responsibilities, making the complex multi-layer authentication process more manageable and maintainable while ensuring comprehensive security through layered verification

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8943318B2Secure messaging by key generation information transfer
Publication Date: 2015.01.27 VERIZON PATENT & LICENSING INC
  • US8943318B2 patent drawing
  • US8943318B2 patent drawing
  • US8943318B2 patent drawing

AI summary

A system is configured to receive a first authentication request from a first device, authenticate the first device, establish a secure connection with the first device based on authenticating the first device, and receive, via the secure connection with the first device, a set of parameters from the first device. The first device is capable of generating an encryption key for a secure message, intended for a second device, based on the set of parameters. The system is also configured to receive a second authentication request from a second device, authenticate the second device and establish a secure connection with the second device based on receiving the second authentication request, and send, via the secure connection with the second device, the set of parameters to the second device. The second user device is capable of generating a decryption key for the secure message based on the set of parameters.