Authentication System Server Verification Protocol

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems lack a standardized method for communication between application servers and authentication servers during possession authentication, making it difficult for application servers to recognize the results of possession authentication.

Innovation Solution

An authentication system that includes an application providing apparatus and an authentication apparatus, where the application server requests possession authentication from the authentication server, receives and verifies the authentication result, and provides application functions to the terminal only if the authentication is valid, enabling easy recognition of possession authentication results.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If communication procedures for possession authentication are not standardized between application server and authentication server, then the authentication server can perform possession authentication, but the application server cannot easily recognize the result of possession authentication

Engineering Contradiction:
Improveauthentication result recognitionVSAvoidcommunication procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the communication parameters by defining standardized message formats including authentication result indicators and verification information. The authentication server transmits structured data containing the authentication result and verification information that the application server can process according to predefined rules, transforming unstructured communication into parameterized standardized interaction.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates a universal communication protocol that enables the authentication server to serve multiple functions: performing possession authentication, generating authentication results, providing verification information, and enabling application servers to recognize results. This standardized procedure makes the authentication system universally applicable across different applications without requiring custom integration for each case.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of manufacture

If the application server implements custom authentication procedures without standardization, then it can concentrate on application development, but it cannot easily recognize possession authentication results

Engineering Contradiction:
Improveapplication development easeVSAvoidauthentication result information
Core Design Contradiction:
Ease of manufactureVSLoss of information

Solution Approach 1:

The patent introduces standardized communication procedures as an intermediary layer between the authentication server and application server. This intermediary protocol ensures that authentication result information is properly transmitted and formatted, preventing information loss while allowing application servers to focus on development without implementing custom authentication logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If verification information is not transmitted from authentication server to application server, then communication is simpler, but the application server cannot verify the validity of the authentication apparatus

Engineering Contradiction:
Improveauthentication apparatus validity verificationVSAvoidcommunication data volume
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts verification information as a separate, essential component from the authentication process. The authentication server transmits specific verification information that the application server can use to independently verify the validity of the authentication apparatus, separating the verification function from the authentication result transmission.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements a feedback mechanism where the application server receives verification information, performs validation, and can determine the legitimacy of the authentication server. This feedback loop ensures that the application server can verify authentication apparatus validity while maintaining controlled communication data volume through targeted information exchange.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11539690B2Authentication system, authentication method, and application providing method
Publication Date: 2022.12.27 CAPY JAPAN INC
  • US11539690B2 patent drawing
  • US11539690B2 patent drawing
  • US11539690B2 patent drawing

AI summary

An application server of an authentication system includes a requesting part that makes a request for possession authentication which is authentication using an authenticator, when the requesting part receives a request for authentication of a user from a terminal, a verifying part that receives an authentication result of the possession authentication and information for verification from the authentication server, and verifies the validity of the authentication server on the basis of the received information for verification, and a providing part that provides a function related to the application to the terminal if the verifying part verifies that the authentication server is valid. The authentication server of the authentication system includes a possession authentication part and a result transmission part that transmits the authentication result of the possession authentication and the information for verification to the application server.