Challenge-Response Authentication System Using Random Numbers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems using portable phones are insecure due to the lack of 'challenge and response' calculations, are difficult to automate, and are limited by fixed communication methods such as optical or contact-based IC card communication.

Innovation Solution

A system where a verification apparatus generates a random number, which is used by a signature generating apparatus to create an electronic signature, and then verified by the verification apparatus, utilizing short-distance communication methods like IR or Bluetooth, allowing for secure and automated authentication across various communication means.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a portable phone screen is used for authentication, then personal information can be displayed and authenticated anytime and anywhere, but the security is low because there is no challenge and response calculation

Engineering Contradiction:
Improveauthentication convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical/optical display-based authentication system with a cryptographic challenge-response system. Instead of displaying static personal information on a phone screen, the system uses mathematical challenges (random numbers) that must be correctly calculated and responded to, providing both convenience and security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The authentication system transitions from static display content to dynamic challenge-response interactions. The verification apparatus sends different random numbers (challenges) each time, and the signature generating apparatus must generate appropriate responses, making the authentication process adaptive and secure against replay attacks.

Inventive Principle:
Principle #15Dynamics

2Reliability

If an IC card is used for authentication, then high security authentication is achieved, but automation is difficult because the IC card cannot initiate access to the verification apparatus

Engineering Contradiction:
Improveauthentication securityVSAvoidaccess automation
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent inverts the traditional IC card authentication model where the card passively receives verification commands. Instead, the signature generating apparatus (equivalent to the IC card) actively initiates access by sending service utilization requests to the verification apparatus, enabling automated initiation of the authentication process.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The signature generating apparatus performs self-service by autonomously initiating the authentication process. It sends service utilization requests to the verification apparatus without requiring manual intervention, and the verification apparatus automatically responds with random numbers for challenge-response authentication.

Inventive Principle:
Principle #25Self-service

3Reliability

If fixed communication means such as optical display/reading or IC card contact communication are used, then authentication can be performed, but adaptability is limited because the communication methods are restricted

Engineering Contradiction:
Improveauthentication functionVSAvoidcommunication means flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal authentication system that can work with multiple communication methods. The verification apparatus and signature generating apparatus can communicate through various means including optical display/reading, IC card contact communication, and other communication methods, making the system adaptable to different communication scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach enhances security by using dynamic random numbers and short-distance communication, enabling secure and automated authentication across diverse communication methods, improving usability and security compared to previous systems.

Implementation Method 1

The service utilizing apparatus and the signature generating apparatus make communication by using a means with an aid of IR (Infra-red Radiation) and/or BT (BlueTooth) and/or a light

Methodology Applied
Scientific EffectIR (Infra-red Radiation): Infrared Radiation

Implementation Method 2

The service utilizing apparatus and the signature generating apparatus make communication by using a means with an aid of IR (Infra-red Radiation) and/or BT (BlueTooth) and/or a light

Methodology Applied
Scientific EffectLight: Light

Data Source

PatentUS7590842B2Service providing system and authentication system, as well as signature generating apparatus, service utilizing apparatus and verification apparatus
Publication Date: 2009.09.15 MAXELL LTD
  • US7590842B2 patent drawing
  • US7590842B2 patent drawing
  • US7590842B2 patent drawing

AI summary

For providing a service providing system and an authentication system, and also a signature generating apparatus, a service utilizing apparatus and a verification apparatus, enabling automatic access, being widely or commonly usable in a communication means thereof, and achieving an authentication function of high security, a system comprises a signature generating apparatus 1, a service utilizing apparatus 2, a verification apparatus 3 and a service providing apparatus 4, wherein the signature generating apparatus 1 has a means for generating a generation key and a verification key, and an electronic signature generating means using the generation key produced, thereby transmitting an electronic signature to the service utilizing apparatus 2, while transmitting the verification key to the verification apparatus 3, wherein the service utilizing apparatus 2 has a service request means, thereby transferring a number to the signature generating apparatus 1, while transmitting the electronic signature to the verification apparatus 3 and the service to be utilized to the verification apparatus 3, wherein the verification apparatus 3 has a number producing means for use of producing the electronic signature, a verification key holding means, and an electronic signature verification means using the verification key therein, thereby transmitting the number to the service utilizing apparatus 2, while transferring a service request to the service providing apparatus 4.