Mutual Authentication via Empirical Channel Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication security methods, such as 'Chip and PIN' technology, are inadequate for secure financial transactions over insecure networks like the Internet, as they rely on trust in merchants and lack proper authentication of merchants to customers, making them vulnerable to interception and fraudulent activities.

Innovation Solution

A method and device for authenticating communication between a customer and a merchant over an insecure network using novel security protocols and cryptographic primitives, establishing a secure channel through a hash function and empirical channels for human verification, ensuring that only authenticated information is shared without revealing sensitive details to untrusted parties.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Chip and PIN technology is used for authentication, then customer-to-merchant authentication is improved, but merchant-to-customer authentication is lacking and security over insecure networks deteriorates

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidnetwork interception vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a Trusted Third Party (TTP) as an intermediary that issues digital certificates to both merchants and customers. This TTP mediates the authentication process by providing cryptographic proof of identity, allowing mutual authentication over insecure networks without direct trust between customer and merchant.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces physical chip-based authentication with cryptographic digital certificate verification. Instead of relying on physical card presence and PIN verification alone, the system uses public key infrastructure and digital signatures to enable secure authentication over electronic networks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If confidential information is transmitted over insecure networks, then transaction convenience is improved, but information security deteriorates due to interception risks

Engineering Contradiction:
Improvetransaction convenienceVSAvoidconfidential information exposure
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent extracts sensitive confidential information from the transmission path by using digital certificates and cryptographic protocols. Only authenticated identity proofs and encrypted data are transmitted over the network, while the actual confidential information remains protected on local devices or with the TTP.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies preliminary cryptographic authentication and encryption before any confidential information is transmitted. Digital certificates verify identities in advance, and cryptographic protocols establish secure channels, preventing interception and misuse of sensitive data during transmission.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If more authentication information is transmitted, then authentication reliability is improved, but bandwidth usage and transmission time increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs authentication information preparation in advance by issuing digital certificates beforehand. These pre-prepared cryptographic credentials can be quickly verified during transactions, reducing authentication time while maintaining high reliability through comprehensive certificate-based verification.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9270450B2Method and device for mutual authentication
Publication Date: 2016.02.23 OXFORD UNIVERSITY INNOVATION LTD
  • US9270450B2 patent drawing
  • US9270450B2 patent drawing
  • US9270450B2 patent drawing

AI summary

A method of authenticating communication between a first and second party (or node) over an insecure, high bandwidth communications network, in which the first party (C) authenticates the second party (M) using a communications protocol comprising a first communications phase through a first communications channel over the insecure, high bandwidth communications network to establish a secure mode of communications between the first and second party, followed by a second communications phase of receiving information from the second party over a second communications channel, such as an empirical channel, and enabling a user to make a human comparison of the information received from the second party with information generated by the first party thereby enabling the user to authenticate the second party in the event of the information from both parties agrees.