Access Control Token Mediation for Secure Service Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control methods for e-commerce platforms struggle to balance flexibility in accessing services from any terminal and location with the need for secure authentication, often leading to issues with fraudulent access and sharing of authentication credentials.

Innovation Solution

A method that distinguishes between access terminals and authentication terminals, using a token generated by the platform to facilitate secure authentication, where the token is transmitted between terminals and verified by an authentication server, incorporating biometric verification and unique authentication terminal registration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional authentication methods (passwords) are used to allow access from any terminal, then flexibility of access is improved, but security control deteriorates due to credential sharing and fraudulent access

Engineering Contradiction:
Improveflexibility of accessVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the authentication process into two distinct phases: a first authentication phase that occurs at the access terminal using a first set of credentials, and a second authentication phase that occurs at a separate authentication terminal using a second set of credentials. This segmentation allows the system to maintain flexibility for accessing services from any terminal while enhancing security through a second verification step at a trusted authentication terminal, thereby resolving the contradiction between access flexibility and security control.

Inventive Principle:
Principle #1Segmentation

2Reliability

If hardware decoders and chip cards are used to ensure legitimate access, then security control is improved, but flexibility of access deteriorates as users are limited to their home location

Engineering Contradiction:
Improvesecurity controlVSAvoidflexibility of access
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system introduces an intermediary authentication terminal that acts as a mediator between the access terminal and the service platform. This authentication terminal verifies the user's identity through a second authentication phase using a second set of credentials, thereby maintaining strong security control. Meanwhile, the access terminal itself can be any device connected to the network, providing flexibility for accessing services from any location. The intermediary authentication terminal resolves the contradiction by providing security verification without restricting the choice of access terminals.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If password-based authentication is used to enable access from any terminal, then ease of operation is improved, but reliability deteriorates due to inability to verify legitimate user authentication

Engineering Contradiction:
Improveease of accessVSAvoidauthentication legitimacy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs a preliminary authentication action at the authentication terminal before granting full access to the service. The authentication terminal receives the first credentials from the access terminal, performs initial verification, and then requires a second set of credentials to be entered at the authentication terminal for final verification. This preliminary action ensures that even though access can be initiated from any terminal easily, the legitimacy of the user is reliably verified through the second authentication phase, resolving the contradiction between ease of operation and authentication reliability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240205214A1Method for controlling access to a good or service distributed by a data communication network
Publication Date: 2024.06.20 HIASECURE
  • US20240205214A1 patent drawing
  • US20240205214A1 patent drawing
  • US20240205214A1 patent drawing

AI summary

A method for controlling access to goods or services offered by a platform from an access terminal includes: transmitting an access request from the access terminal to the platform; transmitting a token including information allowing the access request to be identified by the platform from the platform to the access terminal; transmitting the token from the access terminal to an authentication terminal; transmitting the token and an identifier of the user from the authentication terminal to an authentication server; authenticating the user by the authentication terminal; and, should the authentication be successful: transmitting the information allowing the access request to be identified by the platform and the authenticated identity of the user from the authentication server; and a step in which the platform frees access, from the access terminal, to the goods or services requested by the access request.