Credential Provisioning with Passcode Matching Against MITM Attacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing provisioning methods struggle to ensure that the authenticated user is the same person operating the mobile device receiving access data, and increase the risk of man-in-the-middle attacks due to multiple message transmissions.
Innovation Solution
A method involving a service provider computer receiving an encrypted data packet with a first passcode, comparing it to a second passcode from a user device, and providing access data only when the codes match, using a processing computer to decrypt and verify the credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple message transmissions are used in existing provisioning methods, then credentials can be transmitted between entities, but the likelihood of man-in-the-middle attacks increases and computing resources are consumed significantly
Solution Approach 1:
The system performs preliminary authentication and establishes a secure channel before transmitting credentials. The mobile device and service provider computer authenticate each other and establish encryption keys prior to the actual credential transmission, preventing man-in-the-middle attacks by ensuring the communication path is secure in advance
Solution Approach 2:
The patent introduces an authorizing entity computer as an intermediary that facilitates secure communication between the mobile device and service provider computer. This intermediary manages the authentication process and credential transmission, reducing the attack surface by centralizing security functions and minimizing direct communication between potentially vulnerable endpoints
2Reliability
If multiple entities are involved in the provisioning process, then credentials can be provisioned securely, but the number of message transmissions increases and computing resources are consumed
Solution Approach 1:
The patent combines multiple authentication and credential transmission operations into a single streamlined process. The mobile device authenticates with the service provider computer directly after establishing security through the authorizing entity, merging separate authentication and credential provisioning steps into one efficient flow that reduces computing overhead
Solution Approach 2:
The system uses cryptographic copying where the mobile device creates a local copy of credentials in a secure element after authentication. This allows the credentials to be stored and used locally without requiring continuous communication with remote servers, significantly reducing computing resource consumption for verification operations
3Reliability
If existing provisioning methods are used, then access data can be transmitted to the mobile device, but it is difficult to ensure the authenticated user is the same person operating the device
Solution Approach 1:
The system implements feedback mechanisms where the mobile device must present proof of user presence (such as biometric verification or device passcode) during the authentication process. The service provider computer receives and verifies this feedback before provisioning credentials, ensuring the authenticated user is the actual device operator while maintaining ease of operation through automated verification
Data Source
AI summary
A method and system for provisioning credentials is disclosed. The method includes receiving an encrypted data packet including a first passcode and credentials in encrypted form, and a second passcode. The second passcode is compared to a first passcode. If the passcodes match, then a server computer can transmit a token associated with the credentials to a service provider computer.


