Authentication System Using Key String Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security protocols for authenticating access to secured resources, such as personal and financial information, are vulnerable to interception and spoofing, and often rely on weak password-based systems that can compromise multiple accounts if breached.
Innovation Solution
An authentication system that generates and communicates a key string for authentication, evaluates credentials, and determines the specific secured resource access, ensuring secure and robust authentication without exposing sensitive information, such as passwords or account numbers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If password-based authentication is used, then authentication can be conducted, but the system becomes vulnerable to interception and spoofing
Solution Approach 1:
The patent introduces a key string as an intermediary element between the authentication system and the user. Instead of directly using passwords, the system generates a key string that serves as a mediator for authentication. This key string is communicated to the user through a designated device, creating an intermediary layer that protects the actual authentication credentials from direct exposure and interception.
Solution Approach 2:
The patent extracts the authentication credential (password) from the communication flow between the user and the service client. By removing the password from direct transmission and replacing it with a key string that can be used for authentication without exposing the actual password, the system eliminates the vulnerability to interception while maintaining authentication functionality.
2Ease of operation
If a single password is used for multiple secured resources, then access to multiple resources is simplified, but a security breach in one resource compromises all other resources
Solution Approach 1:
The patent segments the authentication credentials by creating unique key strings for each secured resource. Instead of using a single password across multiple resources, the system generates resource-specific key strings that are tied to individual secured resources. This segmentation ensures that a breach in one resource does not compromise access to other resources, as each resource has its own independent authentication credential.
Solution Approach 2:
The patent applies local quality by making authentication credentials resource-specific rather than universal. Each secured resource receives a key string tailored to that specific resource, creating localized authentication security. This means that the security properties are different for each resource, with each having its own unique credential that cannot be used to access other resources.
3Ease of operation
If passwords are transmitted for authentication, then access can be granted, but sensitive information may be exposed to service clients
Solution Approach 1:
The patent uses a key string as an intermediary that allows authentication to occur without exposing the actual password to service clients. The key string serves as a temporary credential that can be used for authentication purposes but does not reveal the underlying sensitive information. This intermediary mechanism enables the authentication process to function while protecting sensitive information from exposure.
Solution Approach 2:
The patent creates a copy of the authentication credential in the form of a key string that can be used for authentication without being the actual password. This copy contains sufficient information to authenticate the user but does not contain the sensitive information of the original password. The service client receives and processes this copy rather than the original sensitive credential.
Data Source
AI summary
A system and method whereby the identity of a person, entity, device or the like attempting to gain access to a secured resource may be securely authenticated includes a means for receiving from a requester purporting to be an authorized user of a secured resource a request for access by an unauthorized user (such as, for example, a retail store, a service station, an on-line service provider or merchandiser, a healthcare provider, a medical insurer, an information consumer or the like) to the secured resource; a means for generating and communicating to the purported authorized user a key string adapted to provide a basis for authenticating the identity of the requester; a means for receiving an authentication credential associated with the request for access; and a means for evaluating the authentication credential to authenticate the identity of the requester.


