Remote Service Authenticity Verification via Segmented Authentication Paths

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-factor authentication methods are ineffective when the primary authentication terminal is compromised by hardware or software malware, as they rely on classical Public Key Infrastructure (PKI)-based methods that fail to verify the authenticity of the remote service.

Innovation Solution

A computer-implemented method and system that involves multiple authentication arrangements to verify the authenticity of a remote service by sending authentication data through different communication paths, using public keys to decrypt and validate the authenticity, with indicators outputted to determine the authenticity of the remote service, enhancing security even if the primary terminal is compromised.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If classical PKI-based authentication methods are used, then the authentication process is simple and relies on digital certificates, but the system becomes vulnerable to malware compromise on the primary authentication terminal

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidauthentication security against malware
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system is segmented into multiple independent authentication arrangements (first, second, and third arrangements) that verify authenticity through different communication paths. This segmentation ensures that compromise of one path does not affect the others, resolving the vulnerability to malware on a single terminal while maintaining operational simplicity through automated parallel verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary authentication arrangements that act as mediators between the primary terminal and the remote service. These intermediaries independently verify authenticity using different communication paths, providing an additional layer of security without significantly complicating the user experience, as the process remains automated and transparent.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple authentication arrangements with different communication paths are used, then the reliability and detection of man-in-the-middle attacks is improved, but the device complexity increases

Engineering Contradiction:
Improveauthentication security and attack detectionVSAvoidnumber of authentication arrangements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Each authentication arrangement is designed to perform multiple functions: primary authentication, independent verification, and man-in-the-middle attack detection. This multi-functionality allows the system to achieve high reliability and security detection capabilities without proportionally increasing complexity, as the same infrastructure serves multiple security purposes simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system creates copies of the authentication process through multiple independent authentication arrangements that follow the same verification protocol but use different communication paths. This copying approach maintains consistency and reliability while managing complexity through standardized procedures that can be replicated across multiple arrangements.

Inventive Principle:
Principle #26Copying

3Reliability

If the primary authentication terminal is compromised by malware, then classical authentication methods fail to verify remote service authenticity, but additional authentication arrangements provide protection

Engineering Contradiction:
Improveauthenticity verification under compromiseVSAvoidauthentication system architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

By segmenting the authentication process across multiple independent arrangements with separate communication paths, the system ensures that malware compromising the primary terminal cannot affect the independent verification processes. This segmentation provides robust authenticity verification even under compromise conditions, with the complexity managed through modular, standardized authentication components.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11641363B2Methods and systems for verifying the authenticity of a remote service
Publication Date: 2023.05.02 QATAR FOUND FOR EDUCATION SCI & COMMUNITY DEV
  • US11641363B2 patent drawing
  • US11641363B2 patent drawing
  • US11641363B2 patent drawing

AI summary

Disclosed herein are methods and systems that can be used by an end-user to verify both the identity of a remote service (4) and the authenticity of a response provided by the remote service (4), even if the first authentication arrangement (2) used to interact with the remote service (4) is compromised. The end-user requests the remote service (4) to provide evidence of its identity, in the form of potentially different authentication materials. The authentication materials are then verified independently on each additional authentication arrangements (6, 7) and used to determine the authenticity of the response from the remote service (4).