Mobile Device Secret Provisioning via Multi-Channel Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for provisioning devices with secrets for generating One-Time Passwords are either insecure or user-unfriendly, as they often require multiple levels of user input for authentication, compromising security and usability.
Innovation Solution
The method involves a multi-step request process using different communication channels for authentication, including out-of-band methods and encrypted connections, to ensure secure provisioning of secrets to devices with minimal user input, utilizing techniques like two-channel authentication and uniform resource locators (URLs) to confirm message receipt.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure provisioning methods are used, then security is improved, but user friendliness deteriorates due to multiple levels of user input requirements
Solution Approach 1:
The mobile device automatically performs authentication and secret reception without requiring manual user input. The device sends requests, receives credentials, verifies authenticity, and obtains secrets through automated processes, eliminating the need for users to manually provide authentication factors while maintaining strong security through automated two-channel authentication
Solution Approach 2:
The patent replaces manual mechanical authentication processes with automated electronic communication channels. Instead of requiring users to physically provide authentication factors through multiple input levels, the system uses automated message passing over communication channels (such as SMS and HTTP) to achieve authentication and secret provisioning
2Ease of operation
If user friendly provisioning methods are used, then ease of operation is improved, but security deteriorates due to lack of authentication requirements
Solution Approach 1:
The patent introduces authentication credentials as an intermediary element that mediates between the mobile device and the provisioning service. These credentials serve as a secure bridge that verifies device identity without requiring direct user interaction, allowing the system to maintain both user friendliness and security through automated credential-based authentication
Solution Approach 2:
The patent extracts the authentication verification function from manual user input processes and places it within the automated communication protocol. By taking out the need for manual authentication and embedding security verification within the automated message exchange between device and service, the system achieves both ease of operation and strong security
3Ease of operation
If automated provisioning is used, then ease of operation is improved, but device complexity increases due to multiple communication channels and authentication steps
Solution Approach 1:
The patent segments the provisioning process into distinct phases: initial request, credential reception, authentication verification, and secret delivery. Each phase uses appropriate communication channels (SMS for credentials, HTTP for authentication and secret transfer) and can be independently managed, reducing overall complexity while maintaining automation
Data Source
AI summary
A method for provisioning a mobile device with a secret to be used as a basis for generating One-Time passwords includes receiving a first request using a first communications method. The first request includes a mobile device identifier. The method also includes sending a credential message using a second communications method. The credential message includes an authentication credential. The method also includes receiving a second request using a third communications method different from the second communications method. The second request includes information based upon the authentication credential sent by the provisioning service. The method also includes sending the secret if the authentication credential in the credential message corresponds to the information based upon the authentication credential in the second request.


