Mobile Authentication via Intermediary Asymmetric Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods, such as those using PINs and public keys, are vulnerable to interception and misuse during transmission and storage, compromising security, especially in transactions involving sensitive data and financial transfers.

Innovation Solution

An authentication method utilizing a third entity, the Intermediary, to manage communication between the User and the Manager, employing asymmetric cryptography for Control Data and SMS/MMS/TCP/IP protocols for secure information exchange, ensuring that sensitive data like PINs and keys are not directly transmitted, and using a mobile phone terminal with a software program for user authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PINs and public keys are transmitted over the air and stored inside the authentication system, then authentication can be performed, but sensitive information may be captured and misused by malicious users

Engineering Contradiction:
Improveauthentication securityVSAvoidinterception and misuse of sensitive data
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive authentication data (PINs and cryptographic keys) from the transmission channel and storage system. Instead of transmitting or storing these sensitive values, the system uses their cryptographic transformations (hashes, encrypted forms) that can be verified without exposing the original data. This removes the vulnerable elements from the system while preserving authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces cryptographic protocols as intermediaries between the user and the authentication system. Rather than directly transmitting PINs and keys, the system uses cryptographic transformations (hashing, encryption, digital signatures) as mediators that allow verification of authentication credentials without exposing the actual sensitive data. This intermediary layer prevents direct interception and misuse.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If authentication requires transmission of sensitive data, then verification can be performed, but security is compromised during transmission and storage

Engineering Contradiction:
Improveauthentication processVSAvoiddata protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical approach of directly transmitting and storing sensitive data with a cryptographic system. Instead of moving actual PINs and keys through the system, it uses cryptographic transformations (hashing, encryption) that maintain verification capability while eliminating the security risks associated with data transmission and storage. This substitution preserves ease of operation while dramatically improving data protection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Object-affected harmful factors

If sensitive information is isolated and not transmitted, then security is enhanced, but authentication complexity increases

Engineering Contradiction:
Improveprotection from interceptionVSAvoidauthentication system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into distinct cryptographic operations: data transformation, verification, and authentication. By breaking down the authentication mechanism into separate cryptographic steps (hashing, encryption, digital signatures), the system protects sensitive data while managing complexity through modular design. Each segment handles a specific aspect of secure authentication without requiring the entire system to be complex.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2481230B1Authentication method, payment authorisation method and corresponding electronic equipments
Publication Date: 2015.04.29 FERRARI(IT)
  • EP2481230B1 patent drawingFigure 1
  • EP2481230B1 patent drawingFigure 2
  • EP2481230B1 patent drawingFigure 3

AI summary

The authentication method is based on the exchange of text messages between an User electronic equipment, in the form of a mobile phone terminal, and an Intermediary electronic equipment, and between a Manager electronic equipment and an Intermediary electronic equipment; upon a request of authentication of a User by a Manager to an Intermediary, the Intermediary electronic equipment sends to the mobile phone terminal an authentication key by means of an encrypted text message; the mobile phone terminal decrypts the encrypted text message via a cryptography key; the cryptography key has been previously encrypted via a PIN and stored inside the mobile phone terminal; if the mobile phone terminal correctly replies to the encrypted text message by sending to the Intermediary electronic equipment an appropriate encrypted text message, authentication is successful; typically, SMS or MMS and asymmetric encryption are used for implementing this method. The payment authorisation method is based on such authentication method and may involve also a Payer electronic equipment.