Anonymous Authentication Proxy for Credential Obscuring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing web-based authentication techniques in networked computing systems are vulnerable to security attacks, and users face the inconvenience of managing multiple usernames and passwords.

Innovation Solution

An anonymous authentication system that registers and activates client devices, providing them with anonymous credentials such as QuickCodes, QuickUsernames, QuickPINs, QuickPasswords, QuickPhones, and QuickEmails, which are generated on-the-fly and used to obscure authentication information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional username and password authentication is used, then users can access web applications, but the system becomes vulnerable to security attacks and credential theft

Engineering Contradiction:
Improveauthentication securityVSAvoidvulnerability to spoofing and phishing attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an authentication proxy as an intermediary component positioned between the user's client device and the web application server. This proxy intercepts authentication requests, generates anonymous credentials locally, and forwards them to the server. The intermediary shields the server from direct exposure to user credentials and attack vectors, thereby resolving the contradiction between maintaining authentication functionality and improving security against spoofing and phishing attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates anonymous copies of authentication credentials (such as QuickCodes and QuickPasswords) that are locally generated on the client device rather than using real usernames and passwords. These anonymous credentials serve as substitutes that maintain authentication functionality while eliminating the harmful exposure of actual credential information to the server and network, thus improving security without sacrificing access capability.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If users maintain lists of multiple usernames and passwords for different applications, then they can authenticate to various services, but the management and access process becomes inconvenient

Engineering Contradiction:
Improveaccess to multiple applicationsVSAvoidcredential management convenience
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The authentication proxy is designed as a universal credential management system that serves multiple functions: it stores authentication information for various applications, generates appropriate anonymous credentials for different services, and automatically handles the authentication process. This multi-functional approach allows users to access diverse web applications without manually managing separate credential lists for each service, thereby improving ease of operation while maintaining adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables self-service authentication by automatically generating and managing anonymous credentials on the client device without requiring user intervention. The proxy autonomously handles credential retrieval, generation, and transmission to various applications, eliminating the need for users to manually query and manage their own credential lists. This self-service mechanism significantly improves operational convenience while preserving the ability to access multiple applications.

Inventive Principle:
Principle #25Self-service

3Ease of manufacture

If authentication credentials are stored and transmitted in plain text, then the authentication process is simple, but the data becomes exposed to security breaches and attacks

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidexposure of authentication data
Core Design Contradiction:
Ease of manufactureVSLoss of information

Solution Approach 1:

The system transforms authentication credentials from plain text format to anonymous encoded formats (such as QuickCodes and QuickPasswords). These parameter changes maintain the functional equivalence of authentication data while fundamentally altering its structure to prevent exposure. The anonymous credentials undergo cryptographic transformation that preserves authentication capability while eliminating the vulnerability associated with plain text storage and transmission.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The authentication proxy creates and transmits anonymous copies of authentication credentials rather than the actual credentials themselves. These copies are locally generated and transmitted in an encoded format that cannot be directly interpreted or stolen. The copying mechanism preserves the functional purpose of credential transmission while protecting the underlying information from exposure during storage and transmission processes.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20250193156A1Anonymous authentication system and methods for obscuring authentication information in networked computing systems
Publication Date: 2025.06.12 CHANGEFLY INC
  • US20250193156A1 patent drawing
  • US20250193156A1 patent drawing
  • US20250193156A1 patent drawing

AI summary

System and methods for anonymously authenticating a client device and/or user are disclosed. An authentication system can register and/or activate a client device and provide the client device with credentials for accessing or otherwise logging into a third-party application. The client device can provide the third-party application with credentials received from the authentication system and/or self-generated credentials. The third-party application can interact with the authentication system to confirm an identity of the client device and/or authenticate the client device to access the third-party application.