Dynamic Multifactor Authentication via Mobile Challenge-Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods, such as static single-factor and dynamic two-factor systems, are vulnerable to phishing and keyboard logging attacks, and existing two-factor solutions like smartcards and biometrics have limitations in usability and cost-effectiveness for wide-scale implementation.
Innovation Solution
A method and system utilizing a mobile device to generate a second piece of authentication information based on received information, which is then validated to produce an authentication signal, leveraging mobile processing power and reducing the need for additional hardware tokens.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If static single-factor authentication is used, then implementation is simple, but security is vulnerable to phishing and keyboard logging attacks
Solution Approach 1:
The patent transforms static authentication credentials into dynamic ones by implementing time-synchronized challenge-response authentication. The server generates challenges that change over time, and the client responds with time-stamped answers, making captured credentials obsolete after a short window. This dynamic approach resolves the security vulnerability while maintaining implementation simplicity.
Solution Approach 2:
The system performs preliminary verification by validating the client's identity through a challenge-response mechanism before granting access. The server预先 generates challenges and validates responses in advance of actual resource access, preventing unauthorized authentication without requiring complex hardware infrastructure.
2Reliability
If smartcard two-factor authentication is used, then security is improved, but device complexity and cost increase due to required smartcard readers
Solution Approach 1:
The patent replaces the mechanical smartcard reader hardware requirement with software-based authentication mechanisms that run on standard web browsers and servers. The challenge-response protocol is implemented entirely in software, eliminating the need for specialized hardware tokens while maintaining two-factor security through something the user knows (password) and something the user has (browser session/state).
Solution Approach 2:
The authentication system is designed to work across multiple platforms and devices without requiring device-specific hardware. The web-based challenge-response mechanism can be implemented on any device with a web browser, making the system universally applicable rather than tied to specific hardware platforms like smartcards.
3Reliability
If biometric authentication is used, then security is enhanced, but cost and implementation complexity increase significantly
Solution Approach 1:
The patent uses inexpensive, easily deployable web browser-based authentication mechanisms instead of expensive biometric hardware. The challenge-response tokens are ephemeral and generated software-based, requiring no physical manufacturing or deployment of costly biometric sensors while providing sufficient security for the application context.
4Reliability
If dynamic two-factor authentication with tokens is used, then security against phishing is improved, but ease of operation deteriorates due to manual code entry
Solution Approach 1:
The system implements automatic challenge-response verification where the browser automatically sends and processes authentication challenges without requiring manual user intervention. The client software handles the entire authentication sequence automatically, generating and submitting responses based on server challenges, thereby maintaining security while eliminating manual code entry for the user.
Data Source
AI summary
A method of authenticating a user. The method comprises the step of sending an authentication request to a remote authentication device and generating a first piece of authentication information. A mobile device receives the first piece of authentication information from either an access terminal or the remote authentication device. The mobile device of the user generating a second piece of authentication information which is at least partially based on the received first piece of authentication information. The second piece of authentication information is sent to the remote authentication devices and the second piece of authentication information validated. If the second piece of authentication information is successfully validated an authentication signal is generated.


