Restricted Channel for Secure Two-Factor Authentication Code Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing two-factor authentication methods are insecure due to the use of unencrypted communication channels like SMS and email, which can lead to unauthorized access to security codes, especially if a device is lost or stolen.

Innovation Solution

Establishing a restricted communications channel using Mobile Device Management (MDM) APIs to securely transmit security codes, such as one-time passwords, between a server and a client device, ensuring encryption and access restrictions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If security codes are transmitted through unencrypted communication channels like SMS and email, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a restricted communications channel as an intermediary mechanism between the server and client device. This channel acts as a secure mediator that transmits security codes without exposing them to unauthorized access, while still maintaining the convenience of automated delivery. The intermediary channel resolves the contradiction by providing a transmission path that is both automated (maintaining ease of operation) and secure (improving reliability).

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the security parameter of the communication channel from unencrypted to encrypted/restricted. By modifying the channel's security properties rather than the transmission method itself, the system maintains automated delivery (ease of operation) while enhancing security. This parameter change allows security codes to be transmitted securely without requiring manual intervention.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If security codes are sent to a lost or stolen device, then authentication capability is maintained, but security is worsened due to unauthorized access

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary anti-action by establishing security restrictions on the communication channel before any security codes are transmitted. The restricted channel is configured with access controls and encryption in advance, preventing unauthorized access even if the device is lost or stolen. This preliminary security measure counteracts the potential harm of device compromise while maintaining authentication capability.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent applies local quality by restricting access to security codes at the communication channel level rather than requiring device-level authentication. The restricted communications channel has specialized security properties that are localized to the code transmission path, allowing codes to be delivered securely to the legitimate device while being inaccessible to unauthorized users even if they gain physical access to the device.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If security codes are displayed on a lock screen without credential verification, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of operationVSAvoidunauthorized access to security codes
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The restricted communications channel serves as a secure intermediary that delivers security codes directly to the authentication application without requiring display on the lock screen. The channel mediates between the server and the application, ensuring that codes are transmitted securely and made available only within the authenticated context of the application, thereby preventing unauthorized access while maintaining ease of use.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the security code transmission from the general communication system and places it in a dedicated restricted channel. By separating the secure code transmission path from regular communications, the system eliminates the need to display codes on vulnerable interfaces like the lock screen, while still providing easy access to authenticated users through the secure application interface.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10129240B2Distributing security codes through a restricted communications channel
Publication Date: 2018.11.13 OMNISSA LLC
  • US10129240B2 patent drawing
  • US10129240B2 patent drawing
  • US10129240B2 patent drawing

AI summary

Disclosed are various examples for facilitating distribution of security codes for a two-factor authentication scheme or one-time passwords. Security codes can represent one-time passwords or shared secrets used to seed one-time password algorithms. The security codes can be sent through restricted communications channel to a client device. Rather than using an insecure communication link such as SMS for communication of security codes, the security codes can be sent through the restricted communications channel to reduce the possibility of leakage of the security codes.