Two-Channel Authentication Using Separate Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods are vulnerable to attacks such as 'Man in the Middle' and spyware, as they rely on cryptographic techniques that can be broken or insecure mobile devices, and do not effectively protect against interception and modification of secret information during transactions.

Innovation Solution

A method using two separate data networks to authenticate a person by sending an identification code and a single-use authentication token between a terminal and telecommunications equipment, with the user entering a personal access code, ensuring that secret data is distributed across different channels and not interceptable by intercepting one channel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic techniques are used for authentication, then security against interception is improved, but implementation complexity increases and mobile device security requirements become more stringent

Engineering Contradiction:
Improveauthentication securityVSAvoidcryptographic implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is segmented into two independent channels: Channel 1 transmits the identification code from terminal to server, while Channel 2 transmits the authentication token from server to terminal. This segmentation ensures that even if one channel is compromised, the other remains secure, eliminating the need for complex cryptographic protocols while maintaining high security standards.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If secret information is transmitted through a single channel, then communication simplicity is maintained, but vulnerability to interception and modification attacks increases

Engineering Contradiction:
Improvecommunication simplicityVSAvoidinterception and modification attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The solution transitions from a single-dimensional communication channel to a two-dimensional channel structure. The identification code travels through Channel 1 (terminal to server), while the authentication token travels through Channel 2 (server to terminal). This dimensional expansion creates independent transmission paths that are difficult for attackers to intercept and synchronize simultaneously, effectively neutralizing Man-in-the-Middle attacks while preserving communication simplicity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP2619941B1Method, server and system for authentication of a person
Publication Date: 2018.12.12 ONEY BANK
  • EP2619941B1 patent drawingFigure 1
  • EP2619941B1 patent drawingFigure 2~3

AI summary

The invention relates to a method for authentication of a person previously known by a server to own a telephone having a unique identifier and to possess an access code, which method involves: the server sending (53) an identification code to a terminal on request by the latter via a first network; transferring (57) the identification code to the telephone; the server receiving (59), from the telephone via a second network, the identification code in association with the unique identifier; the server (61) generating a single-use authentification token and sending (63) the latter to the telephone; returning (64) the token to the server; and, in parallel: acquiring (67) via the terminal the access code input by the person; and sending (69) said access code to the server; authentication (71) of the person is obtained by the server if the identification code, the unique identifier, the authentication token and the access code correspond.