Automatic Authentication System for Online Accounts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face inconvenience and security risks due to the need for separate authenticator devices for online account authentication, which can be lost, damaged, or stolen, leading to downtime and compromised accounts.

Innovation Solution

An automatic authentication system that runs on a user's computer, generating and transmitting a security code directly to web sites, eliminating the need for a separate authenticator device and enhancing convenience and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a separate authenticator device is used for two-factor authentication, then security is improved, but device complexity and user inconvenience increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the authenticator functionality with the web browser by integrating a background service that automatically generates and transmits security codes. This merging eliminates the need for a separate physical authenticator device while maintaining two-factor authentication security, thereby reducing device complexity without compromising reliability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an intermediary component - a background service running on the user's computer - that mediates between the user's login attempt and the authentication server. This service automatically generates security codes and transmits them to the server, eliminating the need for direct user interaction with a separate authenticator device while preserving security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a separate authenticator device is used, then security code generation is reliable, but ease of operation deteriorates due to manual code entry

Engineering Contradiction:
Improvesecurity code generationVSAvoidauthentication process convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The background service performs self-service by automatically generating security codes and transmitting them to the authentication server without requiring user intervention. The service monitors for login attempts, generates appropriate security codes, and completes the authentication process autonomously, eliminating manual code entry while maintaining reliable security code generation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The background service performs preliminary actions by pre-generating security codes and having them ready before they are needed during the login process. The service continuously monitors for authentication requests and has the capability to immediately provide security codes, eliminating the need for manual code entry and improving ease of operation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a physical authenticator device is used, then security is enhanced, but loss risk increases leading to downtime

Engineering Contradiction:
Improveauthentication securityVSAvoiddowntime due to lost authenticator
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates a virtual copy of the authenticator functionality within the computer's software environment. Instead of relying on a physical device that can be lost or damaged, the authentication capability is replicated as a background service that is inherently tied to the computer system, eliminating the risk of loss and associated downtime while maintaining security.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The background service provides multi-functionality by serving both as a security code generator and as an automatic transmission mechanism. This universal component handles the entire authentication process within the software environment, eliminating dependence on a single physical device and reducing vulnerability to loss or damage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If manual code entry from a separate device is required, then security compliance is maintained, but productivity decreases due to additional user steps

Engineering Contradiction:
Improvesecurity complianceVSAvoidlogin process efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The background service performs self-service by automatically generating and transmitting security codes without requiring user intervention. This maintains security compliance through proper authentication protocols while eliminating the manual steps that reduce productivity, allowing users to log in efficiently without sacrificing security requirements.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical system of manual code entry and transcription with an automated electronic process. The background service electronically generates and transmits security codes directly to the authentication server, substituting the manual mechanical process with an automated system that maintains security compliance while improving login efficiency.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8640213B2Method and system for automatic authentication
Publication Date: 2014.01.28 CA TECH INC
  • US8640213B2 patent drawing
  • US8640213B2 patent drawing
  • US8640213B2 patent drawing

AI summary

A system and method for automatic authentication includes automatically calculating a security code on a computer running a security program. The security program resides on the same computer as a web browser. In response to a user signing into a web based account on a web site accessed by the web browser, automatically verifying that the security program is registered with the web based account. In response to a second factor security code entry request on the web based account, automatically entering the security code into the web based account. The security code is transmitted to the web site transparently to the user for login.