Mutual Authentication Payload Protocol for Client-Server Identity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods in client/server systems are vulnerable to identity theft and other attacks, such as phishing and Man-In-The-Middle attacks, due to reliance on single-factor authentication and the need for users to actively manage and carry Digital Certificates and Private Keys, which is inconvenient and costly.

Innovation Solution

A method employing a Mutual Authentication Payload (MAP) protocol that generates a multi-factor authentication key, creating a MAP from this key for exchange between client and server, and performing integrity verification and content validation, enabling seamless and automated mutual authentication while allowing client portability without the need for users to carry key-pair credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional mutual authentication using Digital Certificates and Private Keys is implemented, then security against identity theft is improved, but user convenience and system cost deteriorate due to the need for users to actively carry and manage key-pair credentials

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs automated mutual authentication where the client and server automatically verify each other's identities using embedded credentials. The client device autonomously presents its identity to the server and verifies the server's identity without requiring user intervention to manage certificates or keys, thus maintaining high security while improving user convenience

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an authentication payload as an intermediary mechanism that encapsulates and manages the complex key-pair credentials. This payload serves as a mediator between the user and the cryptographic system, handling certificate verification and key management automatically, thereby resolving the contradiction between security requirements and user convenience

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If Digital Certificates and Private Keys are carried in portable devices, then authentication capability during roaming is improved, but system cost and device complexity increase

Engineering Contradiction:
Improveroaming capabilityVSAvoidsystem cost
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication credentials (Digital Certificates and Private Keys) directly into the client device's software or hardware infrastructure, eliminating the need for separate portable authentication devices. This integration maintains roaming capability while reducing system cost and device complexity by consolidating multiple functions into a unified authentication mechanism

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If users are required to visually verify and acknowledge Digital Certificate details, then authentication security is improved, but ease of operation deteriorates as users lack the capability to discern certificate appropriateness

Engineering Contradiction:
Improveauthentication securityVSAvoiduser capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements automated certificate verification where the client device automatically validates the server's Digital Certificate without requiring user inspection. The authentication payload encapsulates the verification logic, performing cryptographic checks and validity assessments autonomously, thus maintaining security while eliminating the burden on users to discern certificate details

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8868909B2Method for authenticating a communication channel between a client and a server
Publication Date: 2014.10.21 FAIR ISAAC & CO INC
  • US8868909B2 patent drawing
  • US8868909B2 patent drawing
  • US8868909B2 patent drawing

AI summary

A method for authenticating a communication channel between a client and server has been disclosed. The method employs a mutual authentication payload (MAP) protocol that enables mutual authentication between a client and server system in a convenient user-friendly manner while providing seamless and automated portability to the clients. In the process of mutual authentication, the client verifies that the server entity is indeed the intended entity and is trusted. Likewise, the server verifies if the client entity initiating the exchange is indeed the intended entity and is trusted. Accordingly, this verification process involves multi-factor authentication factors contained within the MAP protocol.