Two-Way Authentication Using One-Way Out-of-Band Channels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current device pairing methods using out-of-band (OOB) channels for secure association are limited by their unidirectional nature, allowing only one-way authentication, which makes them susceptible to man-in-the-middle attacks, even when the channel is tamper-proof but not private.
Innovation Solution
Implementing a two-way authentication method using a non-private, tamper-proof one-way OOB channel, where signal generators and sensors, such as vibrators and accelerometers, create a secure communication channel between devices, ensuring both endpoints are authenticated without requiring a private channel, thus reducing platform costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If a one-way OOB channel is used for device pairing, then device portability and cost are improved, but authentication security deteriorates due to susceptibility to man-in-the-middle attacks
Solution Approach 1:
The patent applies preliminary action by having the first device send a commitment function of a challenge value through the one-way OOB channel before the actual authentication exchange. This commitment is generated in advance and binds the challenge value, preventing attackers from intercepting and replaying authentication messages. The commitment function is computed beforehand and transmitted through the secure one-way channel, establishing a trusted baseline for subsequent authentication verification.
Solution Approach 2:
The patent uses a commitment function as an intermediary mechanism between the one-way OOB channel and the main communication channel. This commitment function acts as a mediator that carries essential authentication information (the challenge value binding) through the insecure one-way channel while maintaining security. The commitment function translates the security requirements into a form that can be safely transmitted through the limited one-way channel, enabling two-way authentication despite the channel's limitations.
2Device complexity
If a one-way OOB channel is used, then device complexity is reduced, but authentication capability deteriorates because only one-way authentication is possible
Solution Approach 1:
The patent applies dimensionality change by moving the critical authentication information (challenge value binding) to a different communication dimension - the one-way OOB channel. Instead of requiring the main bidirectional channel to carry authentication credentials, the invention places the commitment function in the one-way channel dimension. This separates the authentication verification function from the data exchange function, enabling two-way authentication capability while maintaining simple one-way channel architecture.
Solution Approach 2:
The patent uses copying by transmitting a derived form (commitment function) of the challenge value through the one-way channel rather than the challenge value itself. The commitment function is a cryptographic copy that contains sufficient information for verification but cannot be reversed to obtain the original challenge value. This copying approach enables authentication verification through the one-way channel without exposing sensitive authentication credentials.
Data Source
AI summary
Techniques for two-way authentication between two communication endpoints (e.g., two devices) using a one-way out-of-band (OOB) channel are presented. Here, in embodiments, both communication endpoints may be securely authenticated as long as the one-way OOB channel is tamper-proof. Embodiments of the invention do not require the one-way OOB channel to be private to ensure that both endpoints are securely authenticated. Since providing a two-way or private OOB channel adds to the cost of a platform, embodiments of the invention provide for a simple and secure method for two-way authentication that uses only a non-private one-way OOB channel and thus helping to reduce platform cost. Other embodiments may be described and claimed.


