Proxy Authentication Server for Secure Mobile Identity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication mechanisms using mobile phones are insecure due to reliance on third-party notification infrastructures, potential theft of phones, and lack of control over communication networks, leading to vulnerabilities and the need for secure, independent authentication methods.

Innovation Solution

Implementing a proxy authentication server that schedules communications between a calculator, an authentication server, and a notification server, using encryption techniques like SSL/TLS to secure interactions and manage dual-key authentication, ensuring only the enrolled mobile device can decrypt and verify authentication tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional authentication mechanisms using mobile phones and third-party notification infrastructures are used, then authentication can be performed with user convenience, but security is compromised due to reliance on uncontrolled third-party infrastructure

Engineering Contradiction:
Improveuser convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a notification server as an intermediary component that acts as a trusted mediator between the authentication server and the user's mobile device. This notification server is part of the controlled authentication infrastructure, allowing notifications to be delivered securely without relying on uncontrolled third-party message brokers. The intermediary enables the system to maintain security while preserving user convenience by providing a reliable notification delivery mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If third-party notification infrastructures are used for authentication notifications, then implementation cost is reduced and deployment is simplified, but control over communication security is lost

Engineering Contradiction:
Improvedeployment simplicityVSAvoidcommunication security vulnerability
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authentication system into distinct controlled components: an authentication server, a notification server, and client applications. The notification server is a dedicated component that handles notification delivery within the controlled infrastructure, separating the authentication logic from the notification delivery mechanism. This segmentation allows the system to maintain simple deployment while ensuring communication security through controlled, dedicated notification handling rather than relying on general-purpose third-party message brokers.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If mobile phones are used as authentication devices, then users always have the device with them and can receive notifications, but the devices can be stolen or compromised

Engineering Contradiction:
Improvedevice availabilityVSAvoiddevice theft and compromise
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The notification server acts as a trusted intermediary that delivers notifications directly to authenticated client applications on the user's device. This intermediary mechanism ensures that only authorized applications can receive and process authentication notifications, even if the device is compromised. The controlled notification delivery path adds a layer of security that protects against unauthorized access while maintaining device availability for legitimate use.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11665162B2Method for authenticating a user with an authentication server
Publication Date: 2023.05.30 BULL SA
  • US11665162B2 patent drawing
  • US11665162B2 patent drawing
  • US11665162B2 patent drawing

AI summary

A method performs a strong authentication using a mobile terminal and the capability of the user, as proof of an identity. The mobile terminal allows an authentication to be established by communicating with a proxy authentication server and a notification server. These communications are initiated by an authentication server, used for the authentication. Throughout the authentication, the authentication server remains masked by the proxy authentication server. The only interface between the authentication server and the rest of the world is the proxy authentication server.