Proximity-Based Message Recipient Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic message processing systems, such as INTERACT′″ email money transfer, face security risks due to unsecure communication channels and reliance on weak challenge questions that can be easily guessed or intercepted, particularly when a central identity provider is not available.

Innovation Solution

The system employs proximity-based communication, using mechanisms like QR codes or NFC, to securely transmit an introduction message with an encryption key, allowing devices to generate and encrypt challenge responses, which are then decrypted and sent to initiate a data process, enhancing authentication security without modifying existing central servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a central identity provider is used to verify sender and recipient identities, then authentication security is improved, but system complexity and dependency on external services increase

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the identity verification function from the central identity provider and implements it locally on the sender's and recipient's devices. Each device generates and stores its own cryptographic key pair, allowing independent verification without relying on external authentication services. This reduces system complexity and eliminates dependency on central identity providers while maintaining strong authentication security through cryptographic proof of identity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces cryptographic challenge-response mechanisms as an intermediary between devices to verify identities. Instead of direct connection to a central authority, devices exchange cryptographic challenges and responses that prove identity without revealing sensitive information. This intermediary layer enables secure authentication while preserving device independence and reducing central dependency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If challenge questions are used for recipient verification, then authentication is enabled, but security is weakened due to easy guessing or interception by third parties

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical challenge-question system with a cryptographic challenge-response mechanism. Instead of relying on human-generated questions that can be guessed or intercepted, the system uses algorithmically generated cryptographic challenges that are computationally infeasible to solve without the private key. This substitution maintains ease of operation through automated processes while dramatically improving security against guessing and interception attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the fundamental parameters of the authentication challenge from human-readable questions to cryptographic problems. The challenge is transformed from a linguistic puzzle (easy to guess) to a mathematical problem requiring private key possession (hard to solve). This parameter change preserves operational simplicity through automation while enhancing security by making the challenge computationally infeasible to bypass without proper credentials.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If encryption keys are transmitted over communication channels, then secure authentication is enabled, but risk of interception increases

Engineering Contradiction:
Improveauthentication securityVSAvoidinterception risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary key generation and exchange through proximity-based communication before the actual authentication transaction. Devices exchange public keys or authentication tokens when physically close, establishing secure credentials before any remote communication occurs. This preliminary action ensures that subsequent communications use pre-established secure channels, reducing interception risk while maintaining strong authentication security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses disposable, single-use cryptographic tokens or one-time passwords for authentication challenges. Each authentication session generates unique, ephemeral credentials that expire after use. These short-lived authentication objects cannot be reused or intercepted for future attacks, eliminating the long-term security risks associated with persistent encryption keys while maintaining robust authentication security for each transaction.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS11956248B2System and method for message recipient verification
Publication Date: 2024.04.09 ROYAL BANK OF CANADA
  • US11956248B2 patent drawing
  • US11956248B2 patent drawing
  • US11956248B2 patent drawing

AI summary

An electronic device includes a communication interface and at least one processor configured for: transmitting to or receiving from a second electronic device over proximity-based communication channel an introduction message including a first encryption key; receiving, from a server via the at least one communication interface, a challenge notification providing notification of a challenge to be completed to initiate a data process, the challenge notification including or providing access to at least one data field associated with a verification challenge; identifying, from the at least one data field, an encrypted challenge response value; decrypting the encrypted challenge response value with a key corresponding to the first encryption key; and transmitting the decrypted challenge response value to the server to complete the challenge to initiate the data process.