Authentication Token Cryptographic Binding for Secure Client Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication methods in electronic traffic are time-consuming and vulnerable to attacks due to the complexity of 'triangular relationships' between clients, authentication servers, and service providers, especially in scenarios where clients cannot physically present certificates, leading to insecurity in electronic transactions.

Innovation Solution

A method where an authentication token is cryptographically bound to a secret shared by the client and the authentication server, using middleware to verify digital signatures and establish secure connections via SSL/TLS, ensuring the authentication token's integrity and authenticity before transmission, thereby reducing the need for physical certificates and enhancing security against manipulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication methods using triangular relationships between client, authentication server, and service provider are used, then authentication can be performed, but the process becomes time-consuming and complex

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the authentication server from the triangular relationship, creating a direct bilateral authentication channel between client and service provider. The service provider independently verifies the client's digital signature using the public key infrastructure, eliminating the need for the authentication server to mediate the actual authentication process, thus reducing authentication time while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces digital certificates as an intermediary mechanism that enables direct authentication between client and service provider. The certificates, issued by a trusted certification authority, serve as the mediator that allows the service provider to verify the client's identity without requiring real-time involvement of the authentication server, thereby streamlining the authentication process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If physical certificates are used for authentication, then security against manipulation is improved, but the process cannot be applied in electronic traffic where physical presentation is impossible

Engineering Contradiction:
Improvecertificate authenticityVSAvoidelectronic traffic compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces the mechanical system of physical certificate presentation with an electronic digital signature verification system. Instead of physically presenting a certificate, the client electronically signs a message using their private key, and the service provider verifies the signature using the client's public key from their digital certificate. This substitution enables authentication in electronic traffic while maintaining the security properties of physical certificates.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent uses digital copies of certificates in the form of public keys embedded in digital certificates. These digital copies can be transmitted electronically without error and can be verified by the service provider to authenticate the client's identity, making the authentication process adaptable to electronic traffic while preserving the authenticity verification capability of physical certificates.

Inventive Principle:
Principle #26Copying

3Reliability

If public key methods are used for encryption, then security against eavesdropping is improved, but computational intensity increases

Engineering Contradiction:
Improveencryption securityVSAvoidcomputational energy
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the cryptographic operations into two distinct phases: an initial key exchange phase using computationally intensive public key cryptography to establish secure channels, and a subsequent data transmission phase using efficient symmetric encryption. This segmentation allows the system to benefit from the security of public key methods while minimizing their computational overhead by limiting their use to only the necessary key establishment phase.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2289222B1Method, authentication server and service server for authenticating a client
Publication Date: 2019.07.03 DEUTSCHE TELEKOM AG
  • EP2289222B1 patent drawingFigure 1
  • EP2289222B1 patent drawingFigure 2
  • EP2289222B1 patent drawingFigure 3

AI summary

The invention relates to a method for authenticating a client (C) with respect to a service server (S) comprises the following steps: transmitting an authentication token (c) from an authentication server (K) to the client (C) (110); transmitting the authentication token (c) from the client (C) to the service server (S) (120); verifying the authentication token (c) by the service server (S) (130); and deciding on an approval or disapproval of the requested resource, taking a result of the verification by the service server (S) into consideration (140). An authentication server (K) for authenticating a client (C) with respect to a service server (S) comprises a cryptography device for cryptographically attaching the authentication token (c) to a secret (cid), which is shared between the client (C) and the authentication server (K). The invention further relates to a service server (S) for authenticating a client (C) with respect to the service server (S), wherein the service server (S) comprises an authentication token verifier for verifying whether the authentication token (c) was cryptographically attached to a secret (cid) shared between the client (C) and the authentication server (K).