Access Management System Authenticity Verification via Temporary Data Handshake

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access management systems face challenges in enabling users to verify the authenticity of access management systems before providing credential information, particularly in preventing security risks such as identity theft and unauthorized access.

Innovation Solution

A three-way handshake mechanism between the end user and the access management system, where the user is prompted for temporary data and a password, ensuring authentication is flawless by verifying temporary access information and personal information before providing credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users are prompted to provide credential information to access management systems, then access control functionality is enabled, but security risks such as identity theft and unauthorized access increase

Engineering Contradiction:
Improveauthentication securityVSAvoididentity theft risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication actions by sending temporary access information to a registered destination before the user provides credentials. This preliminary verification step allows users to confirm the legitimacy of the access management system before entering sensitive credential information, thereby preventing identity theft and unauthorized access while maintaining proper access control functionality

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification mechanism where temporary access information acts as a mediator between the user and the access management system. This intermediary element allows users to verify the system's authenticity without directly exposing their credentials, reducing security risks while enabling access control

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access management systems request credential information from users, then access control is enforced, but users may be deceived by spoofing or phishing systems

Engineering Contradiction:
Improveaccess control integrityVSAvoidphishing vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification by sending temporary access information to a pre-registered destination associated with the user. This preliminary action occurs before credential collection, allowing users to verify they are interacting with the legitimate access management system rather than a phishing site, thus maintaining access control integrity while preventing deception

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements preliminary anti-action by proactively sending temporary access information to verify the system's authenticity before any credential exchange occurs. This preemptive measure counteracts potential phishing or spoofing attempts by giving users a way to verify legitimacy in advance, preventing harmful deception while maintaining access control

Inventive Principle:
Principle #9Preliminary anti-action

3Productivity

If users provide credential information without verification, then access is granted quickly, but security compromises occur

Engineering Contradiction:
Improveauthentication speedVSAvoidcredential security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs a quick preliminary verification step by sending temporary access information to a registered destination before credential entry. This preliminary action adds minimal time to the authentication process while significantly improving credential security, as users can quickly verify system legitimacy before providing sensitive information

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The user performs self-verification by checking the temporary access information sent to their registered destination and confirming it matches what they would expect from the legitimate access management system. This self-service verification mechanism maintains authentication speed while improving security, as users independently verify legitimacy without adding complex system checks

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10666643B2End user initiated access server authenticity check
Publication Date: 2020.05.26 ORACLE INT CORP
  • US10666643B2 patent drawing
  • US10666643B2 patent drawing
  • US10666643B2 patent drawing

AI summary

Techniques are disclosed for enabling a user to validate the authenticity of a computing system (e.g., an access management system) such as one which controls access to one or more resources. A user can determine the authenticity of an access management system before the user provides credential information to the access management system. A user can be presented at a client system with an interface to request authentication of an access management system. The access management system may provide the user at the client system with temporary access information to submit back to the access management system. The access management system may provide recent personal information to the user at the client system to verify the access management system. Upon verification of the personal information, the access management system may prompt the user for credential information to establish a session.