Two-Channel Authentication Using Separate Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods are vulnerable to attacks such as 'Man in the Middle' and spyware, as they rely on cryptographic techniques that can be broken or insecure mobile devices, and do not effectively protect against interception and modification of secret information during transactions.
Innovation Solution
A method using two separate data networks to authenticate a person by sending an identification code and a single-use authentication token between a terminal and telecommunications equipment, with the user entering a personal access code, ensuring that secret data is distributed across different channels and not interceptable by intercepting one channel.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic techniques are used for authentication, then security against interception is improved, but implementation complexity increases and mobile device security requirements become more stringent
Solution Approach 1:
The authentication process is segmented into two independent channels: Channel 1 transmits the identification code from terminal to server, while Channel 2 transmits the authentication token from server to terminal. This segmentation ensures that even if one channel is compromised, the other remains secure, eliminating the need for complex cryptographic protocols while maintaining high security standards.
2Ease of operation
If secret information is transmitted through a single channel, then communication simplicity is maintained, but vulnerability to interception and modification attacks increases
Solution Approach 1:
The solution transitions from a single-dimensional communication channel to a two-dimensional channel structure. The identification code travels through Channel 1 (terminal to server), while the authentication token travels through Channel 2 (server to terminal). This dimensional expansion creates independent transmission paths that are difficult for attackers to intercept and synchronize simultaneously, effectively neutralizing Man-in-the-Middle attacks while preserving communication simplicity.
Data Source
Figure 1
Figure 2~3
AI summary
The invention relates to a method for authentication of a person previously known by a server to own a telephone having a unique identifier and to possess an access code, which method involves: the server sending (53) an identification code to a terminal on request by the latter via a first network; transferring (57) the identification code to the telephone; the server receiving (59), from the telephone via a second network, the identification code in association with the unique identifier; the server (61) generating a single-use authentification token and sending (63) the latter to the telephone; returning (64) the token to the server; and, in parallel: acquiring (67) via the terminal the access code input by the person; and sending (69) said access code to the server; authentication (71) of the person is obtained by the server if the identification code, the unique identifier, the authentication token and the access code correspond.