Authentication Device Local Factor Cryptographic Transformation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods in electronic communication are vulnerable to unauthorized access and misuse of authentication devices, where attackers can obtain and exploit user authentication information, even if they secure the means themselves.
Innovation Solution
A method utilizing a local factor chosen by the user, where a secret information shared between the authentication device and server is transformed using a two-way cryptographic transformation, with only the transformed reference information stored on the device and the reference information on the server, ensuring the local factor remains exclusive to the user and cannot be retrieved even if the stored information is compromised.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication information is stored on authentication devices or servers, then authentication functionality is enabled, but the system becomes vulnerable to unauthorized access and data compromise
Solution Approach 1:
The patent extracts the local factor from storage on both authentication devices and servers. Instead of storing the local factor, the system stores only transformed reference information on the device and reference information on the server, both of which are useless without the local factor. This extraction eliminates the vulnerability while preserving authentication functionality.
Solution Approach 2:
The patent introduces transformed reference information as an intermediary between the local factor and the authentication server. This intermediary allows authentication to proceed without exposing the local factor, as the transformed reference information can be processed and verified without revealing the original local factor.
2Ease of operation
If the local factor is stored or transmitted, then authentication can be performed, but the local factor becomes vulnerable to retrieval by attackers
Solution Approach 1:
The patent extracts the local factor from the transmission path between authentication device and server. The local factor remains exclusively on the user's device and is never transmitted or stored on external systems, eliminating the risk of interception or unauthorized retrieval while maintaining authentication operation.
Solution Approach 2:
The patent performs preliminary transformation of the local factor into reference information before any transmission occurs. This preliminary action ensures that even if data is intercepted during transmission, the original local factor cannot be retrieved, as only the transformed reference information is transmitted.
3Adaptability or versatility
If authentication data is stored on authentication devices, then authentication functionality is provided, but the device becomes a target for attackers to obtain user information
Solution Approach 1:
The patent extracts sensitive authentication data from the authentication device storage. Only transformed reference information is stored on the device, which cannot be used to derive the local factor or compromise user identity. This extraction maintains authentication functionality while eliminating the vulnerability to data compromise.
Solution Approach 2:
The patent changes the parameter of stored authentication data from the original local factor to transformed reference information. This parameter change ensures that the stored data maintains its functional utility for authentication while becoming computationally infeasible to reverse or compromise for obtaining the original local factor.
Data Source
AI summary
The submitted invention offers a method of authenticating the communication of an authentication device and at least one authentication server using a local factor with creation of secret information shared by the authentication device and the authentication server; the reference information is derived from the secret information shared by the authentication device and the authentication server, where the manner of derivation is the same on the authentication device and on the authentication server; furthermore, the authentication device creates transformed reference information by means of cryptographic transformation from the reference information, where the local factor chosen and entered by the user or obtained from a medium or from the surrounding environment is used as an input in this cryptographic transformation, and where only the transformed reference information is stored on the authentication device and only the reference information is stored on the authentication server.