Challenge Provider Authentication for Mobile Clients
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication systems, such as SSL, are not ideally suited for mobile clients due to limited system resources, and require separate login credentials for each application service, which can be cumbersome and insecure.
Innovation Solution
A system utilizing a challenge provider that employs cryptographic techniques to authenticate clients seeking access to application services, involving a challenge-response mechanism with complementary cryptographic and authentication techniques, and utilizing secure storage and execution circuits, such as smart cards, to ensure secure access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authentication systems like SSL are used in mobile clients, then authentication functionality is provided, but system resource consumption increases and security is compromised
Solution Approach 1:
The patent introduces an authentication service as an intermediary between the mobile client and application services. This service handles the computationally intensive cryptographic operations centrally, allowing mobile clients to authenticate securely without consuming excessive local resources. The authentication service mediates the challenge-response process, performing complex cryptographic computations that would be burdensome for mobile devices.
Solution Approach 2:
The patent replaces conventional SSL cryptographic mechanisms with a challenge-response authentication mechanism using complementary cryptographic techniques. This substitution allows for more efficient authentication on mobile devices by using cryptographic operations better suited to resource-constrained environments while maintaining security through the complementary technique verification.
2Reliability
If separate login credentials are required for each application service, then access control is provided, but system complexity and user burden increase
Solution Approach 1:
The authentication service provides universal authentication across multiple application services. Instead of requiring separate login credentials for each service, the system uses a single authentication mechanism that works across all services. The authentication service handles multiple services centrally, allowing clients to access different application services without managing separate credentials for each.
Solution Approach 2:
The patent merges multiple authentication functions into a single authentication service. Rather than having separate authentication mechanisms for each application service, the system combines them into one centralized service that handles authentication for all services. This consolidation reduces the number of credentials users must manage and simplifies the overall authentication architecture.
3Adaptability or versatility
If conventional authentication systems are used in mobile clients, then authentication is provided, but adaptability to resource-constrained environments is reduced
Solution Approach 1:
The system dynamically adapts to different client capabilities through the challenge provider, which can select appropriate cryptographic techniques based on the client's resources. The authentication service can adjust the complexity of challenges and responses according to whether the client is a resource-rich fixed device or a resource-constrained mobile device, making the system adaptable to various operational environments.
Data Source
AI summary
A system for providing secured access to an application service includes a challenge provider that uses a first cryptographic technique to provide a challenge to a client seeking access to an application service. The client uses a second cryptographic technique to generate a response, and provides the response to an authentication service. The authentication service grants the client access to the application service only if the challenge and response are authenticated using a first authentication technique complementary to the first cryptographic technique and a second authentication technique complementary to the second cryptographic technique, respectively.


