Bridge Server Authentication System for Multi-Server Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods between users and servers are insecure due to reliance on simple username/password combinations, which are easily intercepted, and require users to remember multiple credentials for different servers, making them costly and user-unfriendly.

Innovation Solution

A bridge server manages multi-level authentications for multiple independent servers, using dynamically changing authentication data, location-based security, and biometrics, allowing users to access various services with a single set of credentials and reducing the need for multiple security devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If username/password authentication is used, then authentication is simple to implement, but security is weak and passwords are easily intercepted

Engineering Contradiction:
Improveease of authentication implementationVSAvoidauthentication security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

A bridge server is introduced as an intermediary between the user and multiple independent servers. The bridge server performs centralized authentication using multiple security factors (location-based services, biometrics, secureID tags) and issues dynamic credentials to access various servers, eliminating the need for users to manage multiple passwords directly while strengthening security through layered verification

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple servers require separate authentication credentials, then each server can have dedicated security controls, but users must remember multiple passwords and carry multiple security devices

Engineering Contradiction:
Improveserver-specific security controlVSAvoiduser authentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The bridge server provides universal authentication functionality that works across multiple independent servers (email, banking, e-commerce, etc.). Users authenticate once through the bridge server using their preferred security factors, and the bridge server issues dynamic credentials that work for all connected servers, eliminating the need for multiple separate credentials and security devices

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If complex authentication tasks like location-based security and biometrics are performed by each server, then authentication security is enhanced, but system cost and complexity increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple authentication functions (location-based security, biometrics, secureID tags) are merged and centralized in the bridge server. The bridge server consolidates these complex authentication tasks and shares them among multiple servers through dynamic credential issuance, reducing individual server complexity while maintaining enhanced security through centralized multi-factor verification

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9218480B2Method and system for improved security utilizing location based services for authentication
Publication Date: 2015.12.22 STRIPE LLC
  • US9218480B2 patent drawing
  • US9218480B2 patent drawing
  • US9218480B2 patent drawing

AI summary

An improved authentication method and system is provided where a user securely accesses a variety of target servers for online email, online banking, credit card purchases, ecommerce, brokerage services, corporate databases, and online content (movies, music and software). The method involves a bridge server performing authentication tasks that allow a user to access a server or a group of servers with multiple security levels. The method eliminates the need for the user to remember multiple usernames/passwords for each target server. The method also allows one bridge server and one set of security devices to be used to authenticate the user for multiple servers, thereby reducing security costs and increasing user convenience. A location-based password-ID generating device is also described for secure location-based access.