Reverse Authentication via Out-of-Band Token Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods, such as passwords and one-way verification, are insufficient for ensuring the legitimacy of entities communicating over non-secure channels, like phones or SMS, as they lack mechanisms for reverse authentication, leading to security vulnerabilities and scams.

Innovation Solution

The solution involves authenticating operators by verifying their access to a secured location through a secure out-of-bands channel, where a unique token is provided by the user and stored at a secured location, allowing the user to confirm the operator's legitimacy by retrieving and verifying the token.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (passwords, one-way verification) are used over non-secure channels, then communication convenience is maintained, but security reliability deteriorates due to lack of reverse authentication

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent inverts the traditional authentication model by enabling the user to authenticate the operator (reverse authentication) rather than only the operator authenticating the user. This is achieved through out-of-band verification channels that allow the user to verify the operator's identity independently, directly resolving the security reliability issue while maintaining manageable complexity through established verification technologies.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces out-of-band verification channels as intermediary mechanisms that facilitate reverse authentication without requiring direct modification of the primary communication channel. These intermediary channels (such as separate communication paths or verification systems) enable security enhancement while keeping the main authentication mechanism relatively simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If no reverse authentication mechanism is implemented, then communication channel simplicity is maintained, but vulnerability to scams increases

Engineering Contradiction:
Improvelegitimacy verificationVSAvoidauthentication process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary verification actions through out-of-band channels before the main authentication transaction occurs. By pre-verifying the operator's identity through alternative channels, the system ensures legitimacy verification is in place before sensitive communications begin, enhancing reliability without significantly complicating the operational flow.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If out-of-band verification channels are implemented, then security against scams is improved, but communication channel requirements increase

Engineering Contradiction:
Improvescam preventionVSAvoidchannel compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent designs the out-of-band verification mechanism to be universally applicable across multiple communication channels and contexts. The verification system is constructed to work with various communication mediums (phone, SMS, email, etc.) without requiring channel-specific implementations, thereby maintaining high adaptability while providing robust scam prevention through consistent verification principles.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11139975B2Authentication in non-secure communication channels via secure out-of-bands channels
Publication Date: 2021.10.05 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11139975B2 patent drawing
  • US11139975B2 patent drawing
  • US11139975B2 patent drawing

AI summary

Various embodiments are provided for authenticating an entity in non-secure communication channels via secure out-of-bands channels. An operator may be authenticated to have access to a secured location associated with an entity upon determining the operator retrieved and communicated a unique token, provided by the user and stored at the secured location, back to the user.