Authentication Server Token ID Generation for Secure User Login

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems require users to manage multiple, unique passwords and enter personal information for each website, leading to security challenges, inefficiencies, and outdated information across multiple platforms.

Innovation Solution

A system utilizing a personal electronic device (PED) with an authentication server that generates a unique token ID, allowing users to authenticate and share personal information securely without needing to remember multiple passwords or enter information on each site, with the PED storing encrypted personal data and the server managing authentication keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users manage multiple unique passwords for each website, then security is improved, but user convenience and ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a centralized authentication server as an intermediary between users and multiple recipient systems. This server stores encrypted authentication information and generates unique authentication codes for each recipient system, eliminating the need for users to directly manage multiple passwords while maintaining security through the intermediary's controlled distribution of credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication server provides universal authentication functionality across multiple recipient systems through a single user account. The server can generate different types of authentication credentials (passwords, tokens, codes) for different systems, allowing one authentication mechanism to serve multiple purposes and systems simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If users enter personal information for each website, then authentication accuracy is improved, but time consumption and operational complexity increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary authentication by having users authenticate once with the centralized authentication server before accessing recipient systems. The server pre-generates authentication codes and credentials, so users don't need to re-enter personal information for each website, reducing time consumption while maintaining authentication accuracy through pre-validated credentials.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication server creates and distributes copies of authenticated user credentials to multiple recipient systems. Instead of users repeatedly providing original personal information, the server generates and manages copies of authentication data (codes, tokens, passwords) that can be used across multiple systems without requiring users to re-enter their information.

Inventive Principle:
Principle #26Copying

3Reliability

If recipient systems store user personal information, then authentication capability is improved, but security risk and system vulnerability increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive authentication information management from individual recipient systems and centralizes it in a dedicated authentication server. The server stores encrypted authentication information centrally, while recipient systems only receive and verify authentication codes without storing sensitive user data, thereby reducing security risks at each recipient system while maintaining authentication capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments authentication functionality into separate components: the authentication server handles credential storage and generation, while recipient systems handle verification only. This segmentation allows recipient systems to maintain authentication capability without bearing the security burden of storing sensitive user information, reducing overall system vulnerability.

Inventive Principle:
Principle #1Segmentation

4Ease of operation

If single sign-on is implemented through a principal system, then user convenience is improved, but privacy exposure and trust requirements increase

Engineering Contradiction:
Improveuser convenienceVSAvoidprivacy exposure
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The authentication server implements local quality by allowing users to selectively provide different levels of personal information to different recipient systems based on what is minimally necessary for each service. Instead of exposing all personal information to all systems through a single sign-on, the system tailors information sharing to each specific recipient system's requirements, reducing privacy exposure while maintaining convenience.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3095265B1Identification and/or authentication system and method
Publication Date: 2022.12.28 PIRRWITZ BJOERN
  • EP3095265B1 patent drawingFigure 1
  • EP3095265B1 patent drawingFigure 2~3
  • EP3095265B1 patent drawingFigure 4~5

AI summary

An authentication method allows a user having a personal electronic device (PED) to login to a recipient system. The user establishes an account on an authentication server, provides personal information to the PED, and uniquely identifies the user's PED. The authentication method establishes a unique token ID for the user. Upon interacting with the recipient system, the user is prompted for his token ID. The recipient system communicates with the authentication server to request the user's information. The authentication server sends an authentication request to the user's PED, which prompts the user for a decision to proceed or not. The user, if deciding to proceed with authentication, selects a subset of the user's personal information that is then sent to the recipient system by the PED, the recipient system authenticating the user thereby.