Remote Service Authenticity Verification via Segmented Authentication Paths
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-factor authentication methods are ineffective when the primary authentication terminal is compromised by hardware or software malware, as they rely on classical Public Key Infrastructure (PKI)-based methods that fail to verify the authenticity of the remote service.
Innovation Solution
A computer-implemented method and system that involves multiple authentication arrangements to verify the authenticity of a remote service by sending authentication data through different communication paths, using public keys to decrypt and validate the authenticity, with indicators outputted to determine the authenticity of the remote service, enhancing security even if the primary terminal is compromised.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If classical PKI-based authentication methods are used, then the authentication process is simple and relies on digital certificates, but the system becomes vulnerable to malware compromise on the primary authentication terminal
Solution Approach 1:
The authentication system is segmented into multiple independent authentication arrangements (first, second, and third arrangements) that verify authenticity through different communication paths. This segmentation ensures that compromise of one path does not affect the others, resolving the vulnerability to malware on a single terminal while maintaining operational simplicity through automated parallel verification.
Solution Approach 2:
The patent introduces intermediary authentication arrangements that act as mediators between the primary terminal and the remote service. These intermediaries independently verify authenticity using different communication paths, providing an additional layer of security without significantly complicating the user experience, as the process remains automated and transparent.
2Reliability
If multiple authentication arrangements with different communication paths are used, then the reliability and detection of man-in-the-middle attacks is improved, but the device complexity increases
Solution Approach 1:
Each authentication arrangement is designed to perform multiple functions: primary authentication, independent verification, and man-in-the-middle attack detection. This multi-functionality allows the system to achieve high reliability and security detection capabilities without proportionally increasing complexity, as the same infrastructure serves multiple security purposes simultaneously.
Solution Approach 2:
The system creates copies of the authentication process through multiple independent authentication arrangements that follow the same verification protocol but use different communication paths. This copying approach maintains consistency and reliability while managing complexity through standardized procedures that can be replicated across multiple arrangements.
3Reliability
If the primary authentication terminal is compromised by malware, then classical authentication methods fail to verify remote service authenticity, but additional authentication arrangements provide protection
Solution Approach 1:
By segmenting the authentication process across multiple independent arrangements with separate communication paths, the system ensures that malware compromising the primary terminal cannot affect the independent verification processes. This segmentation provides robust authenticity verification even under compromise conditions, with the complexity managed through modular, standardized authentication components.
Data Source
AI summary
Disclosed herein are methods and systems that can be used by an end-user to verify both the identity of a remote service (4) and the authenticity of a response provided by the remote service (4), even if the first authentication arrangement (2) used to interact with the remote service (4) is compromised. The end-user requests the remote service (4) to provide evidence of its identity, in the form of potentially different authentication materials. The authentication materials are then verified independently on each additional authentication arrangements (6, 7) and used to determine the authenticity of the response from the remote service (4).


