Smartphone-Based Two-Factor Authentication for Network Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current two-factor authentication methods for high-security environments are costly and cumbersome, requiring dedicated devices like smart cards, which can malfunction and are inconvenient for regular use, especially in business environments where high security is needed without excessive additional costs.

Innovation Solution

A system utilizing a smart mobile phone for two-factor authentication, where encryption keys are not stored in non-volatile memory and the phone acts as a possession factor, eliminating the need for a dedicated smart card, with the mobile phone's short-range communication interface enabling secure authentication through radio or light waves, ensuring the encryption keys are not stored within the computer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated smart cards and special keypads are used for two-factor authentication, then security level is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity levelVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by using a smartphone - a device already present in most users' possession - to perform multiple functions including authentication, key storage, and communication with the computer system. This eliminates the need for dedicated smart cards and special keypads, reducing device complexity while maintaining security through the smartphone's existing capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The smartphone acts as an intermediary between the user and the computer system's encryption/decryption operations. It stores encryption keys securely and communicates authentication status to the computer via short-range wireless communication, mediating the authentication process without requiring dedicated authentication hardware in the computer itself

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If encryption keys are stored in non-volatile memory inside the computer, then ease of operation is improved, but security level deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity level
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the encryption key storage function from the computer's non-volatile memory and relocates it to the smartphone. The computer only temporarily holds keys in volatile memory during active sessions, while the smartphone serves as the secure external storage location. This separation ensures that if the computer is compromised or loses power, the encryption keys remain secure in the smartphone

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary authentication actions by having the smartphone verify credentials and establish secure connection before the computer allows access to encrypted data. The smartphone prepares and transmits authentication tokens in advance, ensuring that key access is controlled before any decryption operations occur on the computer

Inventive Principle:
Principle #10Preliminary action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach enhances security by ensuring encryption keys are not stored in non-volatile memory, reduces additional costs, and simplifies user access by leveraging a device most users already carry, providing a high-security system that is easy to use and cost-effective.

Implementation Method 1

the mobile phone's short-range communication interface enabling secure authentication through radio or light waves

Methodology Applied
Scientific EffectRadio wave transmission: Electromagnetic Induction

Data Source

PatentEP3403368B12-factor authentication for network connected storage device
Publication Date: 2022.09.14 HIDDN TECH AS
  • EP3403368B1 patent drawingFigure 1
  • EP3403368B1 patent drawingFigure 2
  • EP3403368B1 patent drawingFigure 3

AI summary

The present invention relates to a method and system for 2-factor authentication for network connected storage devices based on the use of a second communication unit, such as a smart mobile phone.