Mutual Authentication via Inverted Verification Flow

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customers are unable to verify the identity of customer service representatives during calls, making them susceptible to fraudsters who steal personal information by impersonating trustworthy organizations.

Innovation Solution

A mutual authentication system where the customer uses a user device to input a one-time passcode, which is verified by an authentication server, allowing the customer to grant or deny access to the representative's account, ensuring the representative's authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If customers provide personal information to authenticate their identity, then the customer service representative can verify the customer's identity, but customers become susceptible to fraudsters who steal personal information by impersonating trustworthy organizations

Engineering Contradiction:
Improvecustomer identity verificationVSAvoidfraud and information theft
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent inverts the traditional authentication model by enabling the customer to authenticate the representative rather than the representative authenticating the customer. The customer's device receives a challenge from the authentication server and verifies the representative's credentials, turning the authentication flow around to protect against impersonation fraud

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The authentication server acts as an intermediary between the customer's device and the representative's device. It generates challenges, verifies credentials, and mediates the mutual authentication process, ensuring that both parties are properly authenticated without directly exposing sensitive information

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a mutual authentication system is implemented requiring passcode verification, then security against fraud is improved, but the authentication process becomes more complex

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The customer's device autonomously performs authentication operations by receiving challenges from the authentication server, generating responses using stored credentials, and verifying the representative's credentials without requiring manual intervention or complex user actions beyond initiating the process

Inventive Principle:
Principle #25Self-service

3Ease of operation

If traditional authentication methods are used where representatives verify customer identity, then the process is simple for representatives, but customers cannot verify the representative's identity

Engineering Contradiction:
Improverepresentative verification processVSAvoidrepresentative identity verification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication direction is inverted so that the customer's device verifies the representative's credentials through challenges from the authentication server, enabling the customer to confirm the representative's identity while maintaining operational simplicity through automated verification

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS11818125B1Mutual authentication system
Publication Date: 2023.11.14 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US11818125B1 patent drawing
  • US11818125B1 patent drawing
  • US11818125B1 patent drawing

AI summary

Mutual authentication techniques are described in this patent document. For example, when a first person calls a second person, neither of them know that the other person is who he or she says he or she is. Thus, after a second person receives the call, the second person is asked to authenticate himself or herself using a user device. After the second person logs into his or her account, the second person can input on the user device a one-time passcode to authenticate the first person. The user device sends the passcode to an authentication server that allows the first person to send back the inputted one-time passcode to the second person. Upon receiving the inputted one-time passcode, the second person can use his or her user device to indicate that the one-time passcode is correct so that the second person can be authenticated to access the first person's account.