Dynamic Pairing Code Authentication via Risk Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic methods for authentication and key management, such as symmetric and asymmetric encryption, are vulnerable to man-in-the-middle attacks and key compromise, leading to data insecurity, especially in open communication mediums like the internet, where keys and biometric data are susceptible to interception.

Innovation Solution

A method using dynamic pairing codes derived from a proprietary risk analysis algorithm, which combines user and device identifiers to generate authentication scores, establishing trust between endpoints without relying on third-party certificate authorities, and encrypting these codes with special encryption keys to ensure secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If symmetric or asymmetric encryption is used to secure communications, then data confidentiality is improved, but vulnerability to man-in-the-middle attacks and key compromise increases

Engineering Contradiction:
Improvedata confidentialityVSAvoidman-in-the-middle attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication and establishes trust relationships before actual data transmission. Device identifiers are verified and paired in advance, creating a trusted foundation that prevents man-in-the-middle attacks during subsequent communications.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces device identifiers as intermediary elements that mediate between communicating parties. These identifiers act as trusted intermediaries that verify authenticity without requiring direct sharing of secret keys, thereby preventing key compromise while maintaining confidentiality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption keys are shared between users to enable secure communication, then data security is improved, but the risk of key interception and compromise increases

Engineering Contradiction:
Improvedata securityVSAvoidkey interception
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system segments the authentication process into separate components: device identifiers are used for authentication while encryption keys are derived independently. This segmentation prevents key interception because the identifiers themselves are not secret keys and cannot directly compromise the encryption keys.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent employs asymmetric device identifiers that do not require secret sharing. Each device has unique identifiers that can be publicly exchanged without compromising security, breaking the symmetry requirement of traditional key exchange protocols and eliminating the need for secret key distribution channels.

Inventive Principle:
Principle #4Asymmetry

3Measurement precision

If biometric data is stored and transmitted for authentication, then authentication accuracy is improved, but susceptibility to interception and compromise increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoiddata interception
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system extracts and uses only device identifiers for authentication purposes, separating this function from biometric data storage and transmission. By taking out the authentication function and implementing it through identifiers rather than biometric data exchange, the system maintains authentication accuracy while eliminating the security risk of biometric data interception.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If third-party certificate authorities are used to establish trust, then authentication reliability is improved, but dependency on external entities and potential compromise increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidtrust establishment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service authentication where devices autonomously verify each other's identities using their own device identifiers. This eliminates dependency on third-party certificate authorities, reducing both external compromise risks and the complexity of trust establishment while maintaining authentication reliability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10609014B2Un-password: risk aware end-to-end multi-factor authentication via dynamic pairing
Publication Date: 2020.03.31 LOGICMARK INC
  • US10609014B2 patent drawing
  • US10609014B2 patent drawing
  • US10609014B2 patent drawing

AI summary

A method for determining a dynamic pairing code for use in exchanging information between a first and a second communications entity. At the at the first communications entity, determining a first authentication score associated with a first information exchange session between the first and second communications entities, determining a second authentication score associated with a second information exchange session between the first and second communications entities, (the second information exchange spaced apart in time from the first information exchange), combining the first and second authentication scores to create a cumulative risk analysis score, and responsive to the cumulative risk analysis score, generating a dynamic pairing code for use in governing exchange of information during subsequent communications between the first and second communications entities.