Authentication Token With Server-Specific Keys for Secure Registration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication mechanisms, such as entering user names and passwords, are cumbersome, prone to input errors, and pose security risks, particularly during registration with service servers, and require users to remember personalization data, which can be compromised through shoulder surfing or unauthorized access.

Innovation Solution

A method utilizing encrypted communication channels and asymmetric cryptographic key pairs, where personalization data is read from an electronic source and authenticated using a user certificate, generating a server-specific authentication token for secure user identification without transmitting personal data, ensuring the authenticity and security of the authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users enter personalization data manually during registration, then the service server can create personalized user accounts, but the process becomes cumbersome and security risks increase

Engineering Contradiction:
ImprovesecurityVSAvoidregistration process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an authentication token as an intermediary between the user and the service server. The token contains the user's personalization data and cryptographic keys, allowing the server to authenticate the user without manually handling sensitive data. This mediator approach resolves the contradiction by automating the registration process while enhancing security through cryptographic mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the manual mechanical process of typing passwords and personalization data with an automated cryptographic system. The authentication token uses asymmetric cryptography to automatically prove user identity and authorization, eliminating the need for users to manually enter sensitive information while maintaining strong security guarantees.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If users store personalization data in writing or memory, then they can remember credentials, but security risks increase through shoulder surfing or unauthorized access

Engineering Contradiction:
Improvecredential managementVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive personalization data and cryptographic keys from the user's direct control and stores them securely within the authentication token. The user only needs to possess the token, not remember the embedded credentials. This extraction approach resolves the contradiction by removing harmful factors (shoulder surfing risks) while maintaining ease of operation through token possession.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication token can be implemented as a disposable or easily replaceable object (such as a USB key or mobile device). If compromised, the token can be lost or destroyed without affecting the user's ability to authenticate using a replacement token, thereby eliminating the security risks associated with storing credentials in memory or writing.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If the service server verifies passwords manually, then user authentication can be performed, but input errors occur frequently and the process is cumbersome

Engineering Contradiction:
Improveauthentication accuracyVSAvoidauthentication mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the manual password verification process with automated cryptographic verification. The service server uses the public key contained in the authentication token to verify the user's identity through digital signatures or challenge-response protocols. This substitution eliminates input errors while maintaining a relatively simple verification process on the server side.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The authentication token contains a copy of the user's public key and authorization information, allowing the service server to verify the user's identity without requiring the user to manually provide sensitive data. This copying approach resolves the contradiction by enabling accurate automated verification while keeping the authentication mechanism straightforward.

Inventive Principle:
Principle #26Copying

4Adaptability or versatility

If multiple credentials are required for different services, then personalized authentication can be achieved, but users must remember multiple pieces of information

Engineering Contradiction:
Improveservice-specific authenticationVSAvoidcredential memorization
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The authentication token is designed as a universal credential that can be used across multiple service servers. Each token contains service-specific authentication keys that enable the same physical token to provide personalized authentication for different services without requiring users to remember multiple separate credentials. This multi-functionality approach resolves the contradiction by maintaining service-specific authentication capabilities while simplifying user operation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12587520B2Personalized, server-specific authentication mechanism
Publication Date: 2026.03.24 BUNDESDRUCKEREI GMBH
  • US12587520B2 patent drawing
  • US12587520B2 patent drawing
  • US12587520B2 patent drawing

AI summary

The authentication mechanism provides a personalized, server-specific authentication of a user with respect to a service server using an authentication token. The method includes a registration of a user with a service server, which includes a creation of a personalized user account for the user with the service server. Furthermore, a server-specific, asymmetric cryptographic key pair is generated for the user by an authentication token, the key pair including an authentication key and an authenticating key. The authenticating key is made available to the service server and assigned to the personalized user account thereby.