Mobile Identity Authentication with Session Keys and Action Confirmation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile devices face challenges in providing high-security identity authentication for electronic devices with low costs and ease of implementation.
Innovation Solution
A method involving a mobile device and electronic device that exchange session keys to authenticate identity through wireless communication, using different antennas or power levels to ensure secure communication within a preset distance, and user confirmation of actions or codes to verify session integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used, then implementation cost is low, but security is insufficient
Solution Approach 1:
The authentication process is divided into multiple independent steps: generating session key, encrypting action information, user confirmation, and final authentication. Each step can be independently implemented and verified, improving security without requiring complete system redesign.
Solution Approach 2:
A session key is introduced as an intermediary element between the mobile device and electronic device. This session key enables secure communication without requiring the devices to share pre-established secrets, simplifying implementation while enhancing security.
2Reliability
If complex authentication protocols are implemented, then security is improved, but user operation becomes complicated
Solution Approach 1:
The system automatically generates session keys, performs encryption, and verifies authentication without requiring user intervention in these technical processes. The user only needs to confirm the displayed action information, making the complex security protocol transparent to the user.
Solution Approach 2:
The system uses visual display of action information and authentication codes that the user can easily perceive and confirm. The authentication state is clearly indicated through display updates, making the process user-friendly despite the underlying complexity.
3Reliability
If secure distance restrictions are enforced, then security is improved, but communication flexibility is reduced
Solution Approach 1:
The system dynamically adjusts the session key based on the distance between devices. When devices are within the secure distance, normal authentication proceeds. When distance exceeds the threshold, the system detects potential spoofing and adjusts authentication requirements accordingly, providing both security and flexibility.
Solution Approach 2:
The authentication protocol changes parameters such as session key generation and verification requirements based on the measured distance between devices. This allows the system to maintain security for close-range communications while accommodating longer-distance scenarios with additional verification steps.
Data Source
AI summary
An identity authentication method and a mobile device. The mobile device performs receiving a first message of an electronic device within a second distance from the electronic device, where the first message includes a randomly generated session key, randomly generating first action information in response to the first message, and obtaining a second message by encrypting the first action information using the session key, sending the second message to the electronic device. displaying first confirmation information to determine whether the electronic device performs a first action indicated by the first action information, receiving first input used for confirmation, and prompting that identity authentication on the electronic device succeeds, where the second distance is less than or equal to a preset secure distance.


