Mobile Authentication via Intermediary Asymmetric Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods, such as those using PINs and public keys, are vulnerable to interception and misuse during transmission and storage, compromising security, especially in transactions involving sensitive data and financial transfers.
Innovation Solution
An authentication method utilizing a third entity, the Intermediary, to manage communication between the User and the Manager, employing asymmetric cryptography for Control Data and SMS/MMS/TCP/IP protocols for secure information exchange, ensuring that sensitive data like PINs and keys are not directly transmitted, and using a mobile phone terminal with a software program for user authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PINs and public keys are transmitted over the air and stored inside the authentication system, then authentication can be performed, but sensitive information may be captured and misused by malicious users
Solution Approach 1:
The patent extracts the sensitive authentication data (PINs and cryptographic keys) from the transmission channel and storage system. Instead of transmitting or storing these sensitive values, the system uses their cryptographic transformations (hashes, encrypted forms) that can be verified without exposing the original data. This removes the vulnerable elements from the system while preserving authentication functionality.
Solution Approach 2:
The patent introduces cryptographic protocols as intermediaries between the user and the authentication system. Rather than directly transmitting PINs and keys, the system uses cryptographic transformations (hashing, encryption, digital signatures) as mediators that allow verification of authentication credentials without exposing the actual sensitive data. This intermediary layer prevents direct interception and misuse.
2Ease of operation
If authentication requires transmission of sensitive data, then verification can be performed, but security is compromised during transmission and storage
Solution Approach 1:
The patent replaces the mechanical approach of directly transmitting and storing sensitive data with a cryptographic system. Instead of moving actual PINs and keys through the system, it uses cryptographic transformations (hashing, encryption) that maintain verification capability while eliminating the security risks associated with data transmission and storage. This substitution preserves ease of operation while dramatically improving data protection.
3Object-affected harmful factors
If sensitive information is isolated and not transmitted, then security is enhanced, but authentication complexity increases
Solution Approach 1:
The patent segments the authentication process into distinct cryptographic operations: data transformation, verification, and authentication. By breaking down the authentication mechanism into separate cryptographic steps (hashing, encryption, digital signatures), the system protects sensitive data while managing complexity through modular design. Each segment handles a specific aspect of secure authentication without requiring the entire system to be complex.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The authentication method is based on the exchange of text messages between an User electronic equipment, in the form of a mobile phone terminal, and an Intermediary electronic equipment, and between a Manager electronic equipment and an Intermediary electronic equipment; upon a request of authentication of a User by a Manager to an Intermediary, the Intermediary electronic equipment sends to the mobile phone terminal an authentication key by means of an encrypted text message; the mobile phone terminal decrypts the encrypted text message via a cryptography key; the cryptography key has been previously encrypted via a PIN and stored inside the mobile phone terminal; if the mobile phone terminal correctly replies to the encrypted text message by sending to the Intermediary electronic equipment an appropriate encrypted text message, authentication is successful; typically, SMS or MMS and asymmetric encryption are used for implementing this method. The payment authorisation method is based on such authentication method and may involve also a Payer electronic equipment.