Secure Transaction Service for Remote Authentication Device Registration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure user authentication systems over networks face challenges in verifying the authenticity and integrity of biometric devices, particularly when they are remote from the relying party, as there is no assurance that the device is authorized or has not been compromised by hackers.

Innovation Solution

The solution involves a secure transaction service that generates and shares keys between authentication devices and secure transaction servers, using out-of-band communication channels for enhanced security during registration, and employs secure transaction confirmation techniques to ensure that transactions are not tampered with, including the use of trusted user interfaces and query policies to manage authentication capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If authentication devices are remote from the relying party, then user convenience and accessibility are improved, but device authenticity verification and security are worsened

Engineering Contradiction:
Improveuser convenienceVSAvoiddevice authenticity verification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a secure transaction service as an intermediary between the relying party and remote authentication devices. This service generates and manages cryptographic keys, verifies device authenticity through secure communication channels, and mediates the registration process. The intermediary enables remote devices to be verified securely without requiring physical proximity to the relying party, thus resolving the contradiction between user convenience and verification reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary key generation and device registration through secure out-of-band communication channels before actual authentication transactions. The secure transaction service pre-establishes cryptographic key pairs and verifies device identity in advance, creating a trusted foundation that enables subsequent remote authentication operations. This preliminary security establishment allows devices to operate remotely while maintaining verification integrity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive authentication capabilities are disclosed during registration, then security verification is improved, but user privacy is worsened

Engineering Contradiction:
Improvesecurity verificationVSAvoiduser privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements local quality by allowing different levels of authentication capability disclosure for different users or contexts. The secure transaction service enables selective disclosure where only necessary authentication capabilities are revealed during registration, while maintaining comprehensive security verification. This differentiated approach allows the system to adapt the level of information disclosure to specific requirements, improving privacy while maintaining security.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies partial action by implementing optional enhanced verification steps. The basic registration process requires minimal capability disclosure for privacy protection, while offering optional enhanced verification mechanisms that can be activated when higher security assurance is needed. This partial disclosure approach balances privacy protection with security verification needs on a case-by-case basis.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3138265B1Enhanced security for registration of authentication devices
Publication Date: 2020.11.11 NOK NOK LABS INC
  • EP3138265B1 patent drawingFigure 1A
  • EP3138265B1 patent drawingFigure 1B
  • EP3138265B1 patent drawingFigure 2

AI summary

A system, apparatus, method, and machine readable medium are described for enhanced security during registration. For example, one embodiment of a method comprises: receiving a request at a relying party to register an authenticator; sending a code from the user to the relying party through an authenticated out-of-band communication channel; and verifying the identity of the user using the code and responsively registering the authenticator in response to a positive verification.