Information Registration Authentication via Intermediary Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for registering and authenticating security information in business applications lack security, as the Rich Execution Environment (REE) is not secure, allowing tampering and interception of sensitive information during transmission.

Innovation Solution

A method and device for information registration and authentication that involves sending a request to an authentication server, generating and signing standard information with second authentication information, and verifying the identity of the information provider through an identity identifier, ensuring the integrity of the information during transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If security information is transmitted in REE environment, then information transmission convenience is improved, but security is worsened due to interception and tampering risks

Engineering Contradiction:
Improveinformation transmission convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an authentication server as an intermediary between the terminal and business applications. The authentication server verifies the authenticity of standard information using authentication information, preventing unauthorized access and tampering while maintaining transmission convenience through the existing REE environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication by requiring authentication information to be verified before standard information is accepted or processed. This pre-verification step ensures that only authenticated information proceeds through the system, preventing security issues before they occur.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If standard information is saved by service provider, then authentication capability is improved, but security vulnerability is worsened as saved information can be tampered with

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication server acts as an intermediary that verifies the authenticity of standard information using authentication information. This mediation ensures that service providers receive verified information without directly storing sensitive authentication data, reducing security vulnerabilities while maintaining authentication capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical approach of storing raw security information with a cryptographic verification system. Instead of storing and comparing password or biometric data directly, the system uses authentication information and verification mechanisms to prove identity without exposing sensitive data.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Speed

If security information application is invoked in REE, then invocation speed is improved, but information security is worsened due to lack of protection

Engineering Contradiction:
Improveinvocation speedVSAvoidinformation security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The authentication server serves as a secure intermediary that handles verification operations. The security information application can be quickly invoked in REE for user interaction, while all critical verification operations are mediated through the secure authentication server, combining speed with security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication process into two parts: user interaction and information collection occur in the fast REE environment, while verification and authentication occur in the secure environment through the authentication server. This segmentation allows speed where possible and security where critical.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3355511B1Information registration and authentication method and device
Publication Date: 2022.11.02 ADVANCED NEW TECHNOLOGIES CO LTD
  • EP3355511B1 patent drawingFigure 1
  • EP3355511B1 patent drawingFigure 2
  • EP3355511B1 patent drawingFigure 3

AI summary

The present application discloses a method and a device for information registration and authentication. The registration method comprises: sending a request for registering standard information to an authentication server; receiving first authentication information fed back by the authentication server; generating a standard information acquisition request, sending the standard information acquisition request and the first authentication information to a security information application, and acquiring signed standard information and an identity identifier of the standard information that are returned by the security information application after the security information application approves authentication of the first authentication information, wherein the signed standard information is signed by the security information application using second authentication information; and sending the signed standard information, the identity identifier of the standard information, and the first authentication information to the authentication server, to cause the authentication server to register the standard information and the identity identifier of the standard information after the authentication server approves authentication of the first authentication information and approves authentication of the second authentication information according to the signed standard information.