Mutual Authentication Protocol Using Cryptographic Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In online transactions, there is a lack of assurance that the person attending a rendezvous to finalize a transaction is the same individual who initiated the online transaction, as third parties can potentially usurp identities.

Innovation Solution

A mutual authentication protocol involving the generation and exchange of tokens between two entities using cryptographic algorithms and secret keys, allowing entities to verify each other's identities during a second-stage meeting using portable electronic devices for secure authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a delivery code is used for authentication, then the purchaser can be authenticated during delivery, but the security of the transaction is insufficient against identity usurpation

Engineering Contradiction:
Improveauthentication reliabilityVSAvoididentity usurpation risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by generating and exchanging authentication tokens during the first online stage of the transaction, before the physical meeting. Each party receives a token that should correspond to the other party's token if identities are genuine. This preliminary token exchange establishes an authentication foundation that prevents identity usurpation during the second stage, resolving the contradiction between basic authentication reliability and security against usurpation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses tokens as intermediary elements to transfer authentication information between parties. Instead of directly verifying identities through complex protocols or physical proof, the tokens serve as mediators that carry authenticated information. The tokens are generated using cryptographic algorithms with secret keys, creating a secure intermediary mechanism that prevents third parties from usurping identities while maintaining authentication reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If mutual authentication is implemented using cryptographic algorithms and secret keys, then identity usurpation is prevented, but the complexity of the authentication process increases

Engineering Contradiction:
Improveidentity usurpation preventionVSAvoidauthentication protocol complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies copying by creating token copies that replicate authentication information. Instead of requiring complex direct verification protocols, the system generates token copies based on cryptographic algorithms and secret keys. These token copies can be transmitted and verified relatively simply, reducing the operational complexity while maintaining strong security against identity usurpation through the cryptographic foundation.

Inventive Principle:
Principle #26Copying

3Reliability

If tokens are exchanged during the first stage, then authentication is enabled for the second stage, but additional communication steps are required

Engineering Contradiction:
Improveauthentication capabilityVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing the token generation and exchange during the first online stage of the transaction, before the physical meeting. This advance preparation eliminates the need for complex authentication procedures during the second stage, allowing parties to meet and complete the transaction more quickly. The time investment in the first stage is offset by the streamlined second stage process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10504109B2Method for the mutual authentication of entities having previously initiated an online transaction
Publication Date: 2019.12.10 IDEMIA FRANCE SAS
  • US10504109B2 patent drawing
  • US10504109B2 patent drawing

AI summary

Methods and devices for enabling authentication may include a first stage in which a first electronic device of the first entity communicates with a second electronic device of the second entity via a telecommunications network. During the first stage, the first electronic device generates a first token and transmits it from the first electronic device to the second electronic device via the network; and the second electronic device generates a third token and transmits the third token to the first electronic device via the network. During a second stage, authenticating a first non-authenticated entity as being the second entity as a function of a second token contained in a first portable electronic device of the first non-authenticated entity occurs; and authenticating a non-authenticated entity as being the first entity as a function of a fourth token contained in a second portable electronic device of the second non-authenticated entity also occurs.