Access Control Token Mediation for Secure Service Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control methods for e-commerce platforms struggle to balance flexibility in accessing services from any terminal and location with the need for secure authentication, often leading to issues with fraudulent access and sharing of authentication credentials.
Innovation Solution
A method that distinguishes between access terminals and authentication terminals, using a token generated by the platform to facilitate secure authentication, where the token is transmitted between terminals and verified by an authentication server, incorporating biometric verification and unique authentication terminal registration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional authentication methods (passwords) are used to allow access from any terminal, then flexibility of access is improved, but security control deteriorates due to credential sharing and fraudulent access
Solution Approach 1:
The system segments the authentication process into two distinct phases: a first authentication phase that occurs at the access terminal using a first set of credentials, and a second authentication phase that occurs at a separate authentication terminal using a second set of credentials. This segmentation allows the system to maintain flexibility for accessing services from any terminal while enhancing security through a second verification step at a trusted authentication terminal, thereby resolving the contradiction between access flexibility and security control.
2Reliability
If hardware decoders and chip cards are used to ensure legitimate access, then security control is improved, but flexibility of access deteriorates as users are limited to their home location
Solution Approach 1:
The system introduces an intermediary authentication terminal that acts as a mediator between the access terminal and the service platform. This authentication terminal verifies the user's identity through a second authentication phase using a second set of credentials, thereby maintaining strong security control. Meanwhile, the access terminal itself can be any device connected to the network, providing flexibility for accessing services from any location. The intermediary authentication terminal resolves the contradiction by providing security verification without restricting the choice of access terminals.
3Ease of operation
If password-based authentication is used to enable access from any terminal, then ease of operation is improved, but reliability deteriorates due to inability to verify legitimate user authentication
Solution Approach 1:
The system performs a preliminary authentication action at the authentication terminal before granting full access to the service. The authentication terminal receives the first credentials from the access terminal, performs initial verification, and then requires a second set of credentials to be entered at the authentication terminal for final verification. This preliminary action ensures that even though access can be initiated from any terminal easily, the legitimacy of the user is reliably verified through the second authentication phase, resolving the contradiction between ease of operation and authentication reliability.
Data Source
AI summary
A method for controlling access to goods or services offered by a platform from an access terminal includes: transmitting an access request from the access terminal to the platform; transmitting a token including information allowing the access request to be identified by the platform from the platform to the access terminal; transmitting the token from the access terminal to an authentication terminal; transmitting the token and an identifier of the user from the authentication terminal to an authentication server; authenticating the user by the authentication terminal; and, should the authentication be successful: transmitting the information allowing the access request to be identified by the platform and the authenticated identity of the user from the authentication server; and a step in which the platform frees access, from the access terminal, to the goods or services requested by the access request.


