Authentication Token With Server-Specific Keys for Secure Registration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication mechanisms, such as entering user names and passwords, are cumbersome, prone to input errors, and pose security risks, particularly during registration with service servers, and require users to remember personalization data, which can be compromised through shoulder surfing or unauthorized access.
Innovation Solution
A method utilizing encrypted communication channels and asymmetric cryptographic key pairs, where personalization data is read from an electronic source and authenticated using a user certificate, generating a server-specific authentication token for secure user identification without transmitting personal data, ensuring the authenticity and security of the authentication process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users enter personalization data manually during registration, then the service server can create personalized user accounts, but the process becomes cumbersome and security risks increase
Solution Approach 1:
The patent introduces an authentication token as an intermediary between the user and the service server. The token contains the user's personalization data and cryptographic keys, allowing the server to authenticate the user without manually handling sensitive data. This mediator approach resolves the contradiction by automating the registration process while enhancing security through cryptographic mechanisms.
Solution Approach 2:
The patent replaces the manual mechanical process of typing passwords and personalization data with an automated cryptographic system. The authentication token uses asymmetric cryptography to automatically prove user identity and authorization, eliminating the need for users to manually enter sensitive information while maintaining strong security guarantees.
2Ease of operation
If users store personalization data in writing or memory, then they can remember credentials, but security risks increase through shoulder surfing or unauthorized access
Solution Approach 1:
The patent extracts the sensitive personalization data and cryptographic keys from the user's direct control and stores them securely within the authentication token. The user only needs to possess the token, not remember the embedded credentials. This extraction approach resolves the contradiction by removing harmful factors (shoulder surfing risks) while maintaining ease of operation through token possession.
Solution Approach 2:
The authentication token can be implemented as a disposable or easily replaceable object (such as a USB key or mobile device). If compromised, the token can be lost or destroyed without affecting the user's ability to authenticate using a replacement token, thereby eliminating the security risks associated with storing credentials in memory or writing.
3Reliability
If the service server verifies passwords manually, then user authentication can be performed, but input errors occur frequently and the process is cumbersome
Solution Approach 1:
The patent replaces the manual password verification process with automated cryptographic verification. The service server uses the public key contained in the authentication token to verify the user's identity through digital signatures or challenge-response protocols. This substitution eliminates input errors while maintaining a relatively simple verification process on the server side.
Solution Approach 2:
The authentication token contains a copy of the user's public key and authorization information, allowing the service server to verify the user's identity without requiring the user to manually provide sensitive data. This copying approach resolves the contradiction by enabling accurate automated verification while keeping the authentication mechanism straightforward.
4Adaptability or versatility
If multiple credentials are required for different services, then personalized authentication can be achieved, but users must remember multiple pieces of information
Solution Approach 1:
The authentication token is designed as a universal credential that can be used across multiple service servers. Each token contains service-specific authentication keys that enable the same physical token to provide personalized authentication for different services without requiring users to remember multiple separate credentials. This multi-functionality approach resolves the contradiction by maintaining service-specific authentication capabilities while simplifying user operation.
Data Source
AI summary
The authentication mechanism provides a personalized, server-specific authentication of a user with respect to a service server using an authentication token. The method includes a registration of a user with a service server, which includes a creation of a personalized user account for the user with the service server. Furthermore, a server-specific, asymmetric cryptographic key pair is generated for the user by an authentication token, the key pair including an authentication key and an authenticating key. The authenticating key is made available to the service server and assigned to the personalized user account thereby.


