Restricted Channel for Secure Two-Factor Authentication Code Distribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing two-factor authentication methods are insecure due to the use of unencrypted communication channels like SMS and email, which can lead to unauthorized access to security codes, especially if a device is lost or stolen.
Innovation Solution
Establishing a restricted communications channel using Mobile Device Management (MDM) APIs to securely transmit security codes, such as one-time passwords, between a server and a client device, ensuring encryption and access restrictions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If security codes are transmitted through unencrypted communication channels like SMS and email, then ease of operation is improved, but security is worsened
Solution Approach 1:
The patent introduces a restricted communications channel as an intermediary mechanism between the server and client device. This channel acts as a secure mediator that transmits security codes without exposing them to unauthorized access, while still maintaining the convenience of automated delivery. The intermediary channel resolves the contradiction by providing a transmission path that is both automated (maintaining ease of operation) and secure (improving reliability).
Solution Approach 2:
The patent changes the security parameter of the communication channel from unencrypted to encrypted/restricted. By modifying the channel's security properties rather than the transmission method itself, the system maintains automated delivery (ease of operation) while enhancing security. This parameter change allows security codes to be transmitted securely without requiring manual intervention.
2Adaptability or versatility
If security codes are sent to a lost or stolen device, then authentication capability is maintained, but security is worsened due to unauthorized access
Solution Approach 1:
The patent applies preliminary anti-action by establishing security restrictions on the communication channel before any security codes are transmitted. The restricted channel is configured with access controls and encryption in advance, preventing unauthorized access even if the device is lost or stolen. This preliminary security measure counteracts the potential harm of device compromise while maintaining authentication capability.
Solution Approach 2:
The patent applies local quality by restricting access to security codes at the communication channel level rather than requiring device-level authentication. The restricted communications channel has specialized security properties that are localized to the code transmission path, allowing codes to be delivered securely to the legitimate device while being inaccessible to unauthorized users even if they gain physical access to the device.
3Ease of operation
If security codes are displayed on a lock screen without credential verification, then ease of operation is improved, but security is worsened
Solution Approach 1:
The restricted communications channel serves as a secure intermediary that delivers security codes directly to the authentication application without requiring display on the lock screen. The channel mediates between the server and the application, ensuring that codes are transmitted securely and made available only within the authenticated context of the application, thereby preventing unauthorized access while maintaining ease of use.
Solution Approach 2:
The patent extracts the security code transmission from the general communication system and places it in a dedicated restricted channel. By separating the secure code transmission path from regular communications, the system eliminates the need to display codes on vulnerable interfaces like the lock screen, while still providing easy access to authenticated users through the secure application interface.
Data Source
AI summary
Disclosed are various examples for facilitating distribution of security codes for a two-factor authentication scheme or one-time passwords. Security codes can represent one-time passwords or shared secrets used to seed one-time password algorithms. The security codes can be sent through restricted communications channel to a client device. Rather than using an insecure communication link such as SMS for communication of security codes, the security codes can be sent through the restricted communications channel to reduce the possibility of leakage of the security codes.


