Dual-Channel Authentication System with Dynamic Mode Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems for remote access to protected services and information via public networks face challenges in providing easy, flexible, and user-friendly authentication methods that are not dependent on radio coverage and do not require dedicated units, as current network-based authentication methods are inconvenient when radio coverage is lost, and manual input methods are cumbersome.
Innovation Solution
A system that supports communication over a second channel, allowing for two authentication modes: a first mode using the radio network and a second mode using an alternative channel, such as a fixed communication network, with decision means to switch between modes based on availability, ensuring authentication can occur regardless of radio coverage and minimizing user interaction.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If network-based authentication is used, then ease of operation is improved, but reliability deteriorates when radio coverage is lost
Solution Approach 1:
The system changes the communication parameter from radio network to alternative channel based on coverage availability. When radio coverage is lost, the authentication mode switches to use an alternative communication channel, maintaining reliability while preserving ease of operation through automatic switching.
Solution Approach 2:
The authentication system dynamically adapts its communication channel based on radio coverage conditions. The system transitions between network-based and alternative channel-based authentication modes, making the system both easy to operate when available and reliable when radio coverage is lost.
2Reliability
If manual input authentication is used, then reliability is improved by not depending on radio coverage, but ease of operation deteriorates due to considerable user interaction
Solution Approach 1:
The system dynamically selects between automated network-based authentication and manual alternative channel authentication based on radio coverage availability. When radio coverage exists, automated authentication provides ease of operation; when coverage is lost, the system switches to alternative channel mode that maintains reliability with minimal user interaction.
Solution Approach 2:
The system introduces an intermediary alternative communication channel that bridges the gap between radio network authentication and manual authentication. This intermediary channel allows automated authentication to continue even when radio coverage is lost, maintaining both reliability and ease of operation.
3Reliability
If dedicated units are used for authentication, then reliability is improved, but device complexity increases
Solution Approach 1:
The system makes the mobile device universal by enabling it to function both as a radio communication device and as an alternative channel communication device. This multi-functionality eliminates the need for dedicated authentication units while maintaining reliability through the alternative channel capability.
Solution Approach 2:
The system merges the authentication function with the existing mobile device infrastructure. By combining radio network authentication and alternative channel authentication in a single device, the system eliminates dedicated authentication units while maintaining reliability through multiple authentication paths.
Data Source
AI summary
The present invention relates to a system for authentication of an end user of a user station arrangement (10) requesting access to protected information, comprising access server means (20) and authentication means (30), the user station arrangement (10) supporting communication with the authentication means (30) over a first communication channel of a radio network (40). It further supports communication with the authentication means (30) over a second communication channel. The authentication means (30) are adapted to, at reception of a request for access to protected information from a user station arrangement (10), establish if the user station arrangement (10) is reachable over the first communication channel. Said authentication means (30) are adapted to support a first authentication mode and a second authentication mode over said second communication channel, and further comprises decision means for selecting if and/or when the first or second authentication mode is to be used for a user station arrangement (10) requesting access to protected information.


