Two-Factor Authentication for Terminal Attack Log Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the financial payment field, terminal equipment under attack requires analysis of attack alarm information logs, but these logs are sensitive and vulnerable to malicious access, posing a security threat if not properly authorized.
Innovation Solution
A method and system for authorized access to terminal attack alarm information logs using a two-factor authentication process involving public-private key pairs and U-KEY, ensuring only authorized personnel can decrypt and access the logs, enhancing security and confidentiality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If attack alarm information is made accessible for analysis, then the ability to diagnose attack causes is improved, but the security and confidentiality of terminal data is compromised
Solution Approach 1:
The patent segments the authentication process into two distinct factors: something the user knows (password/verification code) and something the user possesses (U-KEY with private key). This segmentation allows the system to maintain security while enabling authorized access to attack alarm information for diagnostic purposes.
Solution Approach 2:
The U-KEY acts as an intermediary security device that mediates between the user and the terminal system. It holds the private key and performs cryptographic operations to authenticate the user without exposing sensitive credentials, thus enabling secure information access while protecting terminal data confidentiality.
2Ease of operation
If traditional single-factor authentication is used, then the ease of operation is improved, but the security against malicious access is insufficient
Solution Approach 1:
The patent merges two authentication factors (knowledge-based password and possession-based U-KEY) into a unified authentication process. This combination maintains operational ease by providing a standardized login interface while significantly enhancing security through multi-factor verification, preventing malicious access that could bypass single-factor authentication.
Data Source
Figure 1
Figure 2
AI summary
This invention is a method and system for authorization to get terminal attack alarm information log, and belongs to the communication technology field. A method for authorization to get terminal attack alarm information log includes: after getting the authentication account with permission to get the attack alarm information log, the server will authenticate the validity of client tool; after the validity passes the authentication, the terminal will send the second data to be authenticated to the client tool, and the client tool will re-send it to the server; after the second data to be authenticated pass the authentication, the server will encrypt such data and generate the second authentication data, and send the second authentication data to the terminal; if the second authentication data pass the authentication, the terminal will get the attack alarm information log, encrypt it and send it to the client tool after encryption. It adopts two-factor authentication during this whole process and thus the safety is guaranteed. In addition, the instruction of getting the attack alarm information log from the terminal will be a lawful act recognized by the server, so that the validity of getting the operation instruction will be ensured.