Bidirectional Dynamic Authentication System for Mobile Terminals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication-authorization mechanisms in the intersection of Internet and mobile telecommunication are insecure due to their reliance on single unidirectional authentication modes, making them vulnerable to cracking and compromising the security and reliability of application services.

Innovation Solution

A bidirectional dynamic authentication-authorization system using randomly generated code data, where an encoding terminal provides continuous code data to mobile and data management terminals, incorporating identification data for secure comparison and encryption, and implementing layered authentication to enhance security and reliability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If single unidirectional authentication mode is used, then authentication process is simple, but security and reliability deteriorate as mechanisms can be cracked easily

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic authentication by continuously generating random code data on both the mobile communication terminal and data management terminal. Instead of static credentials, the system uses time-varying code data that changes with each authentication attempt, making the authentication process adaptive and resistant to cracking while maintaining operational simplicity through automated code generation and comparison.

Inventive Principle:
Principle #15Dynamics

2Reliability

If bidirectional dynamic authentication-authorization is implemented, then security and reliability improve, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the authentication system into two independent but coordinated components: the mobile communication terminal and the data management terminal. Each terminal independently generates and stores code data, and the authentication process segments the verification into code data generation, transmission, and comparison stages. This segmentation reduces overall system complexity by distributing functions across separate components while achieving bidirectional dynamic authentication.

Inventive Principle:
Principle #1Segmentation

3Reliability

If code data is continuously generated and transmitted, then authentication reliability improves, but loss of time increases due to additional authentication steps

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-generating and storing code data on both the mobile communication terminal and data management terminal before actual authentication is needed. When authentication is required, the system simply compares the pre-generated code data rather than generating it in real-time, significantly reducing authentication duration while maintaining high reliability through the use of randomly generated untraceable code data.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7853534B2Authentication-authorization system for mobile communication terminal and method therefor
Publication Date: 2010.12.14 SU MIN CHIEH
  • US7853534B2 patent drawing
  • US7853534B2 patent drawing
  • US7853534B2 patent drawing

AI summary

An authentication-authorization system for a mobile communication terminal and a method therefore are provided. When a mobile communication terminal is in a connect state, code data randomly generated by a remote encoding terminal is continuously provided to the terminal and data management terminal. When an application service program on the mobile communication terminal or an application service terminal connected to the mobile communication terminal need to execute an authentication-authorization, identification data of the mobile communication terminal and its card and code data can be offered to the data management terminal to carry out a bidirectional dynamic authentication-authorization, to determine whether allow the application service program or the application service terminal to keep providing an application service or not. In a further aspect of the embodiment, at least two aforementioned authentication-authorization systems are joined, and a layered authentication-authorization mechanism is adopted, so as to provide a secured and completed system.