Central Server Authentication via Cookie Redirection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication methods are costly for service providers, difficult for users to manage multiple credentials, and lack flexibility, especially for small providers, and impose burdens such as repeated personal information entry and cross-border authentication complexities.

Innovation Solution

A method and system utilizing a central server to facilitate user authentication by redirecting users to authentication service providers, allowing cookie-based identification and authentication, enabling cost-effective and flexible authentication across multiple service providers while minimizing user interaction and credential sharing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication methods (passwords, SMS, biometrics) are implemented by service providers, then user security and identity verification are improved, but implementation cost and operational complexity increase significantly

Engineering Contradiction:
Improveuser authentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a central server as an intermediary between users and service providers. This server manages authentication credentials centrally, allowing service providers to outsource authentication complexity while maintaining security. The central server acts as a mediator that handles the complex authentication logic, freeing individual service providers from implementing and maintaining complex authentication systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The central server provides universal authentication services to multiple service providers through a standardized interface. Instead of each service provider implementing their own authentication system, the central server offers a multi-functional authentication service that works across different providers, reducing overall system complexity and implementation costs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple authentication service providers are used to offer diverse authentication methods, then user convenience and authentication flexibility are improved, but cost for small service providers increases

Engineering Contradiction:
Improveauthentication method flexibilityVSAvoidauthentication system cost
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple authentication service providers into a single centralized authentication system. Instead of small service providers independently integrating with multiple authentication providers (which increases cost and complexity), the central server consolidates these services, allowing small providers to access diverse authentication methods through a single interface at reduced cost.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The central server offers universal access to multiple authentication methods (passwords, SMS, biometrics, etc.) through a standardized interface. This allows service providers of any size to access versatile authentication options without bearing the full cost of implementing each authentication method independently.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If users register with multiple authentication service providers to access different services, then service accessibility is improved, but user burden and time consumption increase

Engineering Contradiction:
Improveservice access capabilityVSAvoiduser registration and authentication time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The central server provides universal authentication that works across multiple service providers through a single user registration. Users authenticate once with the central server, and this authentication is then valid across all connected service providers, eliminating the need to register and authenticate separately with each provider while maintaining access to diverse services.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If service providers implement their own authentication systems to maintain control and security, then authentication security is improved, but cost and operational complexity increase

Engineering Contradiction:
Improveauthentication control and securityVSAvoidservice provider operational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The central server acts as a trusted intermediary that maintains authentication security while improving operational efficiency. Service providers can rely on the central server's authentication capabilities rather than building their own systems, freeing them to focus on their core services. The central server's standardized interface ensures secure authentication while reducing the operational burden on individual providers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3178212B1Method and system for authenticating a user
Publication Date: 2020.04.29 ZEALID AB
  • EP3178212B1 patent drawingFigure 1
  • EP3178212B1 patent drawingFigure 2
  • EP3178212B1 patent drawingFigure 3

AI summary

Method for authenticating a user, comprising the steps of a)providing a central server (101), in communication with at least one authentication service provider (110,120,130), arranged to authenticate users via a respective authentication web interface, and at least one user service provider (150), arranged to provide user services to users via a respective user service web interface; b) providing, for a particular user and using a web browser in an electronic device (170,180), access to the authentication web interface, and upon an authentication of the user, the central server placing a cookie on the electronic device identifying the authentication service provider; c) providing, for the user and using the same web browser executed from the same electronic device, access to the user service web interface, and as a result providing the said cookie to the central server; d) identifying, based upon the said cookie, the authentication service provider; e) redirectingthe web browser to the authentication service provider; f) authenticatingthe user; and g) providinguser authentication information to the user service provider. The invention also relates to a system.