Dynamic Pairing Code Authentication via Risk Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cryptographic methods for authentication and key management, such as symmetric and asymmetric encryption, are vulnerable to man-in-the-middle attacks and key compromise, leading to data insecurity, especially in open communication mediums like the internet, where keys and biometric data are susceptible to interception.
Innovation Solution
A method using dynamic pairing codes derived from a proprietary risk analysis algorithm, which combines user and device identifiers to generate authentication scores, establishing trust between endpoints without relying on third-party certificate authorities, and encrypting these codes with special encryption keys to ensure secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If symmetric or asymmetric encryption is used to secure communications, then data confidentiality is improved, but vulnerability to man-in-the-middle attacks and key compromise increases
Solution Approach 1:
The system performs preliminary authentication and establishes trust relationships before actual data transmission. Device identifiers are verified and paired in advance, creating a trusted foundation that prevents man-in-the-middle attacks during subsequent communications.
Solution Approach 2:
The patent introduces device identifiers as intermediary elements that mediate between communicating parties. These identifiers act as trusted intermediaries that verify authenticity without requiring direct sharing of secret keys, thereby preventing key compromise while maintaining confidentiality.
2Reliability
If encryption keys are shared between users to enable secure communication, then data security is improved, but the risk of key interception and compromise increases
Solution Approach 1:
The system segments the authentication process into separate components: device identifiers are used for authentication while encryption keys are derived independently. This segmentation prevents key interception because the identifiers themselves are not secret keys and cannot directly compromise the encryption keys.
Solution Approach 2:
The patent employs asymmetric device identifiers that do not require secret sharing. Each device has unique identifiers that can be publicly exchanged without compromising security, breaking the symmetry requirement of traditional key exchange protocols and eliminating the need for secret key distribution channels.
3Measurement precision
If biometric data is stored and transmitted for authentication, then authentication accuracy is improved, but susceptibility to interception and compromise increases
Solution Approach 1:
The system extracts and uses only device identifiers for authentication purposes, separating this function from biometric data storage and transmission. By taking out the authentication function and implementing it through identifiers rather than biometric data exchange, the system maintains authentication accuracy while eliminating the security risk of biometric data interception.
4Reliability
If third-party certificate authorities are used to establish trust, then authentication reliability is improved, but dependency on external entities and potential compromise increases
Solution Approach 1:
The system implements self-service authentication where devices autonomously verify each other's identities using their own device identifiers. This eliminates dependency on third-party certificate authorities, reducing both external compromise risks and the complexity of trust establishment while maintaining authentication reliability.
Data Source
AI summary
A method for determining a dynamic pairing code for use in exchanging information between a first and a second communications entity. At the at the first communications entity, determining a first authentication score associated with a first information exchange session between the first and second communications entities, determining a second authentication score associated with a second information exchange session between the first and second communications entities, (the second information exchange spaced apart in time from the first information exchange), combining the first and second authentication scores to create a cumulative risk analysis score, and responsive to the cumulative risk analysis score, generating a dynamic pairing code for use in governing exchange of information during subsequent communications between the first and second communications entities.


