Authentication Service Token Extraction for Wearable Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The risk of compromising third-party services during authentication processes for wearable devices and clients, where a compromised service provider can capture authentication tokens, putting both the client and the service at risk.

Innovation Solution

Implementing a system where a generic user identifier (GUID) and device access token are used to authenticate clients with third-party services, with the authentication service generating a unique identifier that is communicated to the client, allowing the client to access the service without directly sending the service authentication token, thus mitigating the risk of token capture.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the device authorization service acts as an intermediary to facilitate authentication between clients and third-party services, then authentication is enabled and communication is facilitated, but the service provider becomes a vulnerable point where malicious parties can capture authentication tokens

Engineering Contradiction:
Improveauthentication facilitationVSAvoidtoken capture risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication token from the communication path between the device authorization service and the third-party service. Instead of the service provider handling or transmitting the actual authentication token, a different mechanism is used that allows authentication to occur without the token being exposed to the service provider, thereby eliminating the capture risk while maintaining operational facilitation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a new intermediary mechanism that replaces the traditional token-based approach. Instead of using authentication tokens that can be captured, the system uses a mediator that enables verification and authentication without requiring the service provider to handle sensitive token data, thus maintaining the intermediary function while removing the security vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If authentication tokens are transmitted through the device authorization service, then clients can authenticate with third-party services, but the communication channel becomes a security risk that puts both the client and service at risk

Engineering Contradiction:
Improveservice access capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The authentication token is extracted from the communication channel between the client and the third-party service through the device authorization service. The system enables service access capability by allowing authentication to occur through an alternative mechanism that does not require transmitting the actual token through the potentially compromised communication channel, thus maintaining versatility while improving reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If the service provider is compromised during authentication, then malicious parties can capture authentication tokens, but implementing additional security measures may complicate the authentication process

Engineering Contradiction:
Improvesecurity protectionVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs an intermediary mechanism that provides security protection without significantly increasing authentication process complexity. The mediator handles the secure verification and authentication in a way that is transparent to the users and does not require complex additional steps from the clients or service providers, thus achieving reliability enhancement while minimizing complexity increase.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11470067B1Secure authentication of devices
Publication Date: 2022.10.11 AMAZON TECH INC
  • US11470067B1 patent drawing
  • US11470067B1 patent drawing
  • US11470067B1 patent drawing

AI summary

Disclosed are various embodiments for an authentication service. A unique identifier is associated with a device access token for a client to be authenticated. An authentication identifier is sent to an authenticated client. The client to be authenticated communicates the authentication identifier and unique identifier to the authentication service to complete authentication.