Mutual Authentication via Cryptographic Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional authentication methods are one-sided, relying heavily on users to secure their credentials, making them vulnerable to attacks like phishing and 'man-in-the-middle' attacks, especially when accessing services over insecure networks.

Innovation Solution

A cryptographic method for mutual authentication between user devices and service provider systems, using public/private key pairs to verify identities and ensure both parties provide credentials, with the ability to maintain secrecy of private keys and transparency for users through a downloadable app.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional one-sided authentication is used, then service providers can verify user credentials, but users cannot verify service provider authenticity making them vulnerable to phishing and man-in-the-middle attacks

Engineering Contradiction:
Improveauthentication securityVSAvoidvulnerability to phishing and man-in-the-middle attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies inversion by reversing the traditional authentication model where only the service provider verifies the user. Instead, both parties perform mutual verification: the user device verifies the service provider's identity through cryptographic validation of the service endpoint identifier, and the service provider verifies the user's credentials. This bidirectional verification eliminates the vulnerability to phishing and man-in-the-middle attacks by ensuring both parties are authentic before establishing a connection.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces cryptographic protocols and digital certificates as intermediaries to enable secure mutual verification. The service endpoint identifier acts as an intermediary that the user device validates to confirm the service provider's authenticity, while digital certificates and cryptographic signatures serve as mediators to establish trusted communication channels. This intermediary mechanism allows verification without directly exposing sensitive credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If users are required to secure their credentials, then authentication can be performed, but users represent soft targets for attackers compared to service provider systems

Engineering Contradiction:
Improveauthentication capabilityVSAvoiduser vulnerability as soft target
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent enables self-service by allowing user devices to autonomously verify service provider authenticity through cryptographic validation of service endpoint identifiers. The user device independently performs verification without relying on the service provider to authenticate themselves, shifting the burden of verification to the client side. This empowers users to protect themselves against phishing attacks without requiring sophisticated security infrastructure.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent inverts the traditional authentication dynamic by requiring the service provider to prove their identity to the user, rather than only the user proving identity to the service provider. Through mutual authentication protocols, the service provider must present valid credentials and cryptographic proofs of authenticity, making it harder for attackers to impersonate service providers and reducing user vulnerability.

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If mutual authentication is implemented, then security against phishing and man-in-the-middle attacks is improved, but authentication complexity increases

Engineering Contradiction:
Improveprotection against authentication attacksVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses cryptographic intermediaries and standardized protocols to manage the complexity of mutual authentication. By introducing digital certificates, cryptographic signatures, and service endpoint identifier validation as intermediary layers, the system achieves secure mutual authentication without requiring complex custom implementations. These standardized intermediaries simplify the overall system architecture while maintaining high security.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If credentials are transmitted over public networks, then service access is enabled, but credentials are vulnerable to eavesdropping attacks even when encrypted

Engineering Contradiction:
Improveservice access capabilityVSAvoideavesdropping vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive credential information from the authentication process by using cryptographic proof mechanisms. Instead of transmitting actual passwords or sensitive credentials over the network, the system uses digital signatures and cryptographic proofs that verify authenticity without exposing the underlying secret information. This extraction of sensitive data from transmission eliminates eavesdropping vulnerabilities while maintaining service access capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11831792B2Mutual authentication of computer systems over an insecure network
Publication Date: 2023.11.28 THINOPS CAPITAL LLC
  • US11831792B2 patent drawing
  • US11831792B2 patent drawing
  • US11831792B2 patent drawing

AI summary

Methods and systems are provided for mutual authentication between an agent, such as a user (142), and a service host system (128), such as a service provider system, via an insecure and/or untrusted communications network (140). In exemplary embodiments, an initial enrolment sequence (300, 400) is mediated by an authentication server (102) to establish an association between the service host system (128) having an identifier (SPID), an agent (142) that is assigned an identifier (UID) known to the service provider, and a client device (116) having a device identifier (DevID), which is used to access the service, along with a set of credentials comprising cryptographic signatures generated by the service host system (128) and client device (116) using corresponding private keys. The resulting data and credentials may be disclosed publicly, remain valid so long as the private keys are not compromised, and can be used subsequently for mutual authentication between the client device (116) and the service host system (128).