Authentication Objects with Attestation for Secure User Interface

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication techniques face challenges in balancing security and usability, particularly in large and complex computing networks, where stringent password requirements often lead to user difficulties, resulting in insecure practices such as writing down or storing passwords insecurely.

Innovation Solution

A graphical user interface that allows users to select and utilize authentication objects, which are representations of authentication credentials, enabling easy access without manual input, using cryptographic verification and attestation to ensure security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If stringent password requirements are implemented, then data security is improved, but usability deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates visual representations (thumbnails) of authentication credentials that users can select and use for authentication. Instead of requiring users to manually enter complex passwords, the system copies the authentication capability into a visual form that can be easily selected and dragged to authentication fields, resolving the contradiction between security and usability.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical action of manually typing passwords with a graphical drag-and-drop operation. Users simply drag the credential thumbnail to the authentication field, eliminating the need to type complex passwords while maintaining security through cryptographic verification of the authentication objects.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual credential entry is required, then security verification is improved, but user experience deteriorates

Engineering Contradiction:
Improvesecurity verificationVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically manages authentication credentials by creating visual representations that users can select. The authentication process is self-service in that users simply select and drag their credential thumbnail without needing to manually input any authentication information, improving user experience while maintaining security through automated cryptographic verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-processing authentication credentials into visual thumbnails that are ready for selection. This preliminary preparation eliminates the need for manual entry during the authentication moment, improving user experience while the cryptographic verification ensures security is maintained.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If complex authentication processes are used, then security is improved, but automation resistance deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidautomated agent access
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent uses visual distinctions (different colors and thumbnails) to represent different authentication credentials. This visual differentiation makes it difficult for automated agents to programmatically determine which credential to use, as the selection process requires human visual recognition and decision-making, thereby resisting automation while maintaining security through cryptographic verification.

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS10050787B1Authentication objects with attestation
Publication Date: 2018.08.14 AMAZON TECH INC
  • US10050787B1 patent drawing
  • US10050787B1 patent drawing
  • US10050787B1 patent drawing

AI summary

Representations of authentication objects are selectable through a user interface, such as through a drag and drop operation. When an authentication object is selected by a user, a corresponding authentication object (e.g., in the form of an authentication claim) is transmitted to s system for authentication. The authentication object may contain information that is sufficient for authentication with the system and the information may include an attestation to the state of a computing environment from which the authentication object is transmitted.