Client Authentication Using Dynamic Policy-Based Encoded Passcodes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods such as password-based, multi-factor, certificate-based, and token-based systems are vulnerable to phishing, device loss, key theft, and high costs, respectively, necessitating a more secure and dynamic approach.
Innovation Solution
A policy-based authentication method using a Regulated Activation Network (RAN) model generates a hierarchical passcode structure, where each authentication attempt uses a unique encoded passcode, ensuring randomness and security through computational modeling and dynamic policy generation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If password-based authentication is used, then implementation is simple, but it is vulnerable to phishing attacks and password guessing
Solution Approach 1:
The patent introduces a biometric template as an intermediary between the user and the authentication system. Instead of directly using passwords or biometric data, the system uses a transformed biometric template that cannot be reverse-engineered to obtain the original biometric data or password, thus providing security while maintaining usability
Solution Approach 2:
The patent replaces traditional password-based mechanical authentication with a biometric-based authentication system. The biometric template transformation mechanism substitutes the need for users to remember and input passwords, while the transformed template provides cryptographic security against phishing and guessing attacks
2Reliability
If multi-factor authentication is used, then security is improved, but it is prone to situations when devices are lost or unavailable
Solution Approach 1:
The patent creates a universal authentication system where a single biometric template can serve multiple authentication purposes. The transformed biometric template can be used across different devices and contexts without requiring multiple separate authentication mechanisms, thus maintaining security while improving device availability
Solution Approach 2:
The system enables self-service authentication through biometric data that users inherently possess. The biometric template transformation allows the system to verify user identity using the user's own biometric characteristics, eliminating the need for external devices that could be lost or unavailable
3Reliability
If certificate-based authentication is used, then security is enhanced, but it is vulnerable to the theft of private keys
Solution Approach 1:
The patent extracts the essential security function from traditional certificate-based authentication by using biometric templates instead of private keys. The transformed biometric template provides the same cryptographic security function without the vulnerability of private key storage and management
Solution Approach 2:
The system uses transformed biometric templates that can be easily regenerated and updated. Unlike private keys that must be securely stored for long periods, the biometric template can be transformed into different forms and is inherently tied to the user's living biometric data, reducing the impact of potential compromises
4Reliability
If token-based authentication is used, then security can be very high, but it is expensive when generating secure tokens and problematic when leaked
Solution Approach 1:
The patent creates a copy of the biometric data in the form of a transformed template that serves the same authentication purpose as expensive secure tokens. The transformed biometric template can be transmitted and stored without the high generation costs associated with cryptographic tokens, while providing comparable security
Solution Approach 2:
The system uses transformed biometric templates that are computationally inexpensive to generate compared to secure tokens. These templates can be rapidly regenerated if compromised, unlike expensive tokens that require complex cryptographic operations to replace
Data Source
AI summary
The present invention relates to a method for authenticating a Client in a Client-Server architecture. The method encodes the Client's input passcode using a Regulated Activation Network computational model to create a Hierarchical model. Depending upon a Policy shared between the Client and the Server, different combinations of encoded passcodes generated from the Hierarchical model, are selected. After every successful authentication operation, a new policy is generated. Because of these new policies, for every authentication attempt, the Client inputs the same passcode but the passcode communicated over the network is always different. The advantages of this method include random encoded passcode generation for the Client's identity verification. This randomness ensures that the generated encoded passcodes are never repeated in two successive authentication attempts. The use of Models, Policies, and the Client's passcode together makes the authentication method highly robust.


