Mobile Device Secret Provisioning via Multi-Channel Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for provisioning devices with secrets for generating One-Time Passwords are either insecure or user-unfriendly, as they often require multiple levels of user input for authentication, compromising security and usability.

Innovation Solution

The method involves a multi-step request process using different communication channels for authentication, including out-of-band methods and encrypted connections, to ensure secure provisioning of secrets to devices with minimal user input, utilizing techniques like two-channel authentication and uniform resource locators (URLs) to confirm message receipt.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure provisioning methods are used, then security is improved, but user friendliness deteriorates due to multiple levels of user input requirements

Engineering Contradiction:
ImprovesecurityVSAvoiduser friendliness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mobile device automatically performs authentication and secret reception without requiring manual user input. The device sends requests, receives credentials, verifies authenticity, and obtains secrets through automated processes, eliminating the need for users to manually provide authentication factors while maintaining strong security through automated two-channel authentication

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical authentication processes with automated electronic communication channels. Instead of requiring users to physically provide authentication factors through multiple input levels, the system uses automated message passing over communication channels (such as SMS and HTTP) to achieve authentication and secret provisioning

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If user friendly provisioning methods are used, then ease of operation is improved, but security deteriorates due to lack of authentication requirements

Engineering Contradiction:
Improveuser friendlinessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces authentication credentials as an intermediary element that mediates between the mobile device and the provisioning service. These credentials serve as a secure bridge that verifies device identity without requiring direct user interaction, allowing the system to maintain both user friendliness and security through automated credential-based authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the authentication verification function from manual user input processes and places it within the automated communication protocol. By taking out the need for manual authentication and embedding security verification within the automated message exchange between device and service, the system achieves both ease of operation and strong security

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If automated provisioning is used, then ease of operation is improved, but device complexity increases due to multiple communication channels and authentication steps

Engineering Contradiction:
Improveease of operationVSAvoidcomplexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the provisioning process into distinct phases: initial request, credential reception, authentication verification, and secret delivery. Each phase uses appropriate communication channels (SMS for credentials, HTTP for authentication and secret transfer) and can be independently managed, reducing overall complexity while maintaining automation

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8606234B2Methods and apparatus for provisioning devices with secrets
Publication Date: 2013.12.10 GEN DIGITAL INC
  • US8606234B2 patent drawing
  • US8606234B2 patent drawing
  • US8606234B2 patent drawing

AI summary

A method for provisioning a mobile device with a secret to be used as a basis for generating One-Time passwords includes receiving a first request using a first communications method. The first request includes a mobile device identifier. The method also includes sending a credential message using a second communications method. The credential message includes an authentication credential. The method also includes receiving a second request using a third communications method different from the second communications method. The second request includes information based upon the authentication credential sent by the provisioning service. The method also includes sending the secret if the authentication credential in the credential message corresponds to the information based upon the authentication credential in the second request.