Authentication System Server Verification Protocol
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems lack a standardized method for communication between application servers and authentication servers during possession authentication, making it difficult for application servers to recognize the results of possession authentication.
Innovation Solution
An authentication system that includes an application providing apparatus and an authentication apparatus, where the application server requests possession authentication from the authentication server, receives and verifies the authentication result, and provides application functions to the terminal only if the authentication is valid, enabling easy recognition of possession authentication results.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If communication procedures for possession authentication are not standardized between application server and authentication server, then the authentication server can perform possession authentication, but the application server cannot easily recognize the result of possession authentication
Solution Approach 1:
The patent changes the communication parameters by defining standardized message formats including authentication result indicators and verification information. The authentication server transmits structured data containing the authentication result and verification information that the application server can process according to predefined rules, transforming unstructured communication into parameterized standardized interaction.
Solution Approach 2:
The patent creates a universal communication protocol that enables the authentication server to serve multiple functions: performing possession authentication, generating authentication results, providing verification information, and enabling application servers to recognize results. This standardized procedure makes the authentication system universally applicable across different applications without requiring custom integration for each case.
2Ease of manufacture
If the application server implements custom authentication procedures without standardization, then it can concentrate on application development, but it cannot easily recognize possession authentication results
Solution Approach 1:
The patent introduces standardized communication procedures as an intermediary layer between the authentication server and application server. This intermediary protocol ensures that authentication result information is properly transmitted and formatted, preventing information loss while allowing application servers to focus on development without implementing custom authentication logic.
3Reliability
If verification information is not transmitted from authentication server to application server, then communication is simpler, but the application server cannot verify the validity of the authentication apparatus
Solution Approach 1:
The patent extracts verification information as a separate, essential component from the authentication process. The authentication server transmits specific verification information that the application server can use to independently verify the validity of the authentication apparatus, separating the verification function from the authentication result transmission.
Solution Approach 2:
The patent implements a feedback mechanism where the application server receives verification information, performs validation, and can determine the legitimacy of the authentication server. This feedback loop ensures that the application server can verify authentication apparatus validity while maintaining controlled communication data volume through targeted information exchange.
Data Source
AI summary
An application server of an authentication system includes a requesting part that makes a request for possession authentication which is authentication using an authenticator, when the requesting part receives a request for authentication of a user from a terminal, a verifying part that receives an authentication result of the possession authentication and information for verification from the authentication server, and verifies the validity of the authentication server on the basis of the received information for verification, and a providing part that provides a function related to the application to the terminal if the verifying part verifies that the authentication server is valid. The authentication server of the authentication system includes a possession authentication part and a result transmission part that transmits the authentication result of the possession authentication and the information for verification to the application server.


