Virtual Phone Number Authentication via Secure Channel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current two-factor authentication methods, such as using a mobile phone number for SMS-based authentication, are vulnerable to man-in-the-middle attacks and rely on fixed security data, which can be compromised, leading to potential breaches in security.

Innovation Solution

A method that involves registering a user with a security service to obtain a virtual mobile phone number not associated with their actual phone, allowing secure transmission of authentication data through a secure channel, with optional obfuscation and rerouting of messages to enhance security, and using a unique identifier for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If SMS-based authentication using user's actual phone number is used, then user convenience is improved, but security is worsened due to vulnerability to man-in-the-middle attacks

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a virtual phone number as an intermediary between the user and the authentication system. Instead of directly using the user's actual phone number, the system routes authentication SMS through a virtual number that the user controls. This intermediary layer prevents direct exposure of the user's real phone number to potential attackers while maintaining the convenience of SMS-based authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If fixed security data is used for authentication, then authentication process is simplified, but security is worsened as fixed data can be compromised

Engineering Contradiction:
Improveauthentication process complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements dynamic security measures where the virtual phone number and authentication routing can be changed or revoked. Unlike fixed security data, the system allows for dynamic updates to authentication parameters, enabling the user to obtain new virtual numbers or change routing configurations if compromise is suspected, thereby maintaining security without permanently complicating the authentication process.

Inventive Principle:
Principle #15Dynamics

3Speed

If direct SMS transmission to user's phone is used, then authentication speed is improved, but security is worsened due to lack of secure channel

Engineering Contradiction:
Improveauthentication speedVSAvoidsecurity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system introduces a secure routing intermediary that mediates between the authentication server and the user's phone. The virtual phone number acts as a secure channel intermediary, allowing fast SMS-based authentication while adding layers of security through controlled routing and the ability to verify message authenticity through the virtual number layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10630669B2Method and system for user verification
Publication Date: 2020.04.21 CYPHERCOR INC
  • US10630669B2 patent drawing
  • US10630669B2 patent drawing
  • US10630669B2 patent drawing

AI summary

A first server receives a text message addressed to a first text destination and including authentication information The first server establishes a secure connection between the first server and a first mobile device associated with a first user, one of the first user and the first mobile device associated with the first text destination. The authentication information is then provided from the first server to the first mobile device via the secure connection.