Split Authentication Credentials for Secure Software Client Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for authenticating software client applications lack efficiency and security, particularly in ensuring the confidentiality and integrity of data transmitted between client devices and third-party servers, as they often require user interaction and do not effectively exclude application distribution entities from accessing sensitive data.

Innovation Solution

A method involving the generation of an asymmetric pair of cryptographic keys or security token information, split into partial information components, where one partial information is transmitted via a secure channel to the client device alongside the software application, and the other via a different channel, ensuring only the client and server can authenticate each other without involving the application distribution entity in the decryption process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used for software client applications, then the application distribution entity can manage and distribute applications, but the security and confidentiality of data transmitted between client devices and third-party servers is compromised because the application distribution entity can access sensitive data

Engineering Contradiction:
Improvedata confidentialityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication credentials are segmented into two separate components: a first partial information transmitted through the application distribution entity via the first secure communication channel, and a second partial information transmitted directly to the client device via a second communication channel. This segmentation ensures that the application distribution entity cannot reconstruct the full authentication credentials, thereby protecting data confidentiality while maintaining a manageable authentication system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where the first partial information acts as a mediator that enables the client device to establish secure communication with the third-party server without requiring the application distribution entity to have access to the complete authentication credentials. This intermediary approach resolves the contradiction by allowing distribution entity involvement in the authentication process while preventing access to sensitive data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If manual authentication processes are implemented, then user control over authentication can be maintained, but the process becomes time-consuming and inefficient

Engineering Contradiction:
Improveauthentication speedVSAvoiduser interaction requirement
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The authentication process is designed to be self-service oriented, where the client device automatically receives and processes both the first partial information (through the application distribution entity) and the second partial information (via the second communication channel). The device autonomously combines these partial informations to establish secure communication, eliminating the need for manual user intervention and significantly improving authentication speed while maintaining ease of operation.

Inventive Principle:
Principle #25Self-service

3Reliability

If a single secure communication channel is used for transmitting authentication credentials, then the transmission process is simple, but the application distribution entity can potentially access and compromise the credentials

Engineering Contradiction:
Improveauthentication securityVSAvoidcommunication channel structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication credentials are divided into two separate partial informations that are transmitted through different communication paths. The first partial information is transmitted through the application distribution entity via the first secure communication channel, while the second partial information is transmitted directly to the client device via a second communication channel. This segmentation ensures that even if one channel is compromised, the complete authentication credentials remain secure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a dimensional change in the communication architecture by adding a second communication channel that operates independently from the first secure communication channel. This creates a multi-dimensional transmission structure where authentication credentials are distributed across different communication dimensions, enhancing security while managing complexity through structured channel design.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP3511852B1Method for providing an enhanced level of authentication related to a secure software client application that is provided, by an application distribution entity, in order to be transmitted to a client computing device; system, software client application instance or client computing device, third party server entity, and program and computer program product
Publication Date: 2021.04.28 DEUTSCHE TELEKOM AG
  • EP3511852B1 patent drawingFigure 1~2

AI summary

The invention relates to a method for providing an enhanced level of authentication related to a secure software client application that is provided, by an application distribution entity, in order to be transmitted, using a telecommunications network, to a client computing device in view of software code of the software client application being executed by the client computing device, wherein a first secure communication channel is established - in view of transmitting an instance of the software client application to the client computing device - between the client computing device and the application distribution entity, and wherein a second secure communication channel is established between the application distribution entity and a third party server entity, wherein the method comprises the following steps: -- in a first step, an asymmetric pair of cryptographic keys and/or a security token information is generated as a protected information in view of subsequently allowing for an authenticated transmission of data - provided by the software client application instance upon it being executed by the client computing device - to the third party server entity, wherein the protected information is generated by the third party server entity and/or by a trusted entity, and wherein a first partial information and at least a second partial information is derived from the protected information, -- wherein in a second step, subsequent to the first step, the first partial information and the at least second partial information is transmitted to the client computing device, the first partial information being transmitted - besides the software client application instance - using at least the first secure communication channel, and the at least second partial information being transmitted using a third communication channel, different from the first secure communication channel, wherein at least the first partial information and the second partial information are required to obtain the protected information.