Electronic Reauthentication via Dual-Channel Token Association
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods, such as codes and passwords, are vulnerable to theft and brute force attacks, making them insecure and user-unfriendly, and existing alternatives like card-based certificates are complex to implement and not widely available.
Innovation Solution
A method and device for electronic reauthentication that creates an association between a telephone communication address and an additional communication address, using confirmation tokens exchanged over different communication channels to verify user control, ensuring secure and easy-to-use authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If code-based or password-based authentication is used, then authentication can be provided, but security is compromised due to risk of theft and brute force attacks
Solution Approach 1:
The authentication process is segmented into multiple independent verification steps: (1) verifying control of telephone communication address through token exchange, (2) verifying control of additional communication address through token exchange, and (3) creating association between these addresses and the communication party. Each segment provides a layer of security that must be satisfied independently, making theft and brute force attacks significantly more difficult.
2Reliability
If card-based certificates are used, then authentication security is improved, but device complexity and implementation difficulty increase
Solution Approach 1:
The patent replaces the mechanical card-based certificate system with an electronic communication-based system. Instead of requiring physical cards and complex PKI infrastructure, the system uses electronic token exchange through communication channels (telephone, email, SMS) that are already widely available. This substitution maintains security while dramatically reducing infrastructure complexity and implementation difficulty.
3Reliability
If multiple codes and passwords are required, then authentication security may be improved, but ease of operation deteriorates due to user burden
Solution Approach 1:
The system enables self-service authentication by verifying control of communication addresses through automated token exchange. Users simply receive tokens through their communication channels (telephone, email, SMS) and confirm them, without needing to memorize multiple codes or passwords. The system automatically manages the authentication process, making it both secure and user-friendly.
Data Source
AI summary
The present invention relates to a method for electronic reauthentication of a communication party (12, 22). The method further relates to a device for electronic reauthentication of a communication party. A basic idea of the present invention is to have a communication party, which employs a service, state two different communication addresses, one being a telephone number, via which the communicating party may authenticate herself to a provider (11, 21) of the service.


