Authentication Server Mediator for Secure Terminal Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional identity verification methods, such as password-based systems, do not meet stringent security requirements, especially in network transactions, and are vulnerable to threats like malware and unauthorized access.

Innovation Solution

An authentication server is used to verify terminal devices by generating transaction data, which includes encrypted packages, and requires software initiation on the terminal for verification, utilizing golden keys and short-range wireless communication protocols like NFC for secure access to network services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional password-based verification is used, then ease of operation is improved, but security reliability deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an authentication server as an intermediary between the user terminal and the application server. This mediator performs additional verification by sending authentication requests to the terminal's installed software, which generates unique authentication codes. This intermediary layer enhances security reliability without significantly impacting ease of operation, as the verification process is automatically handled in the background.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The verification process is segmented into multiple independent stages: initial login verification, authentication server intervention, terminal software verification, and service authorization. By dividing the verification into separate functional modules, the system achieves higher security reliability through layered verification while maintaining ease of operation through automated workflow management.

Inventive Principle:
Principle #1Segmentation

2Reliability

If additional authentication server verification is added, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication server acts as a specialized intermediary component that handles verification logic centrally. Rather than complicating the terminal device or application server, the authentication server absorbs the additional verification complexity, allowing the existing system components to remain relatively simple while achieving enhanced security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The terminal software serves multiple functions: it acts as the user's authentication credential, generates unique authentication codes, and communicates with the authentication server. This multi-functional design reduces the need for separate dedicated verification devices, thereby limiting the increase in device complexity while improving security reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If encrypted transaction data is delivered to terminal, then security reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The terminal's installed software automatically performs decryption and verification of the encrypted transaction data delivered by the authentication server. This self-service mechanism handles the complex cryptographic operations without requiring user intervention, thereby maintaining ease of operation while achieving enhanced security reliability through encrypted data transmission.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9876786B2Method for verifying security data, system, and a computer-readable storage device
Publication Date: 2018.01.23 IDGATE CORP
  • US9876786B2 patent drawing
  • US9876786B2 patent drawing
  • US9876786B2 patent drawing

AI summary

The disclosure herein is related to a method for verifying security data, a system, and a computer-readable storage device. The system includes an application server for providing service, and receiving a service request made by a terminal. The system also includes an authentication server for providing identification authentication for receiving a request made by the application server for verifying the terminal. The authentication server sends a signal to the terminal for initiating an authentication process, and processing authentication with the terminal. The authentication server delivers transaction data for the terminal to complete the service access when the connection between the server and terminal is verified. The terminal is permitted to access the service when the terminal passes the authentication and submits a request form according to the data to the application server.