Centralized Application Authentication Management via Back-End Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for users accessing wireless networks and application servers are complex, insecure, and require users to manage multiple access data for different software applications, especially when using multiple mobile terminals.

Innovation Solution

A method where the back-end server of a wireless network centrally stores and manages application authentications, allowing users to access multiple software applications from various mobile terminals without needing to transmit application authentications, using a SIM card or hardware security module as the authentication medium, and automatically forwarding authentication requests to the back-end server for validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users transmit application authentication from each mobile terminal to the application server, then authentication can be performed for each terminal, but the complexity of authentication management increases and security risks arise from storing authentication data on multiple terminals

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the application authentication data from the mobile terminals and stores it centrally on the back-end server. When authentication is needed, the back-end server transmits the authentication data to the application server. This removes the burden of storing and managing authentication data from multiple user devices, reducing security risks and simplifying user management while maintaining authentication capability across multiple terminals.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If users manually manage application authentication for each software application, then authentication can be performed, but the ease of operation deteriorates due to the need to remember and enter multiple credentials

Engineering Contradiction:
Improveauthentication convenienceVSAvoidtime for authentication
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system implements self-service authentication where the back-end server automatically manages and transmits application authentication data without requiring user intervention. The server retrieves the appropriate authentication credentials from its storage and forwards them to the application server automatically, eliminating the need for users to manually enter credentials and significantly reducing authentication time.

Inventive Principle:
Principle #25Self-service

3Reliability

If application authentication is stored on the back-end server, then security is improved by centralizing credential management, but the device complexity increases due to additional server functionality

Engineering Contradiction:
Improvecredential securityVSAvoidback-end server complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The back-end server is designed with multi-functionality, serving both as the network authentication server and as a credential management system for application-level authentication. By consolidating these functions into a single server component, the patent avoids the need for separate dedicated credential storage systems, thereby improving security through centralization while minimizing the increase in overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11849326B2Authentication of a user of a software application
Publication Date: 2023.12.19 AUDI AG
  • US11849326B2 patent drawing

AI summary

Method and system for authenticating a user comprising: transmitting a network authentication of a user, which is provided by an authentication medium, from a mobile terminal belonging to the user to a back-end server of a wireless network to carry out authentication, connecting the mobile terminal to the wireless network, starting a software application to carry out authentication with respect to an application server accessible via the wireless network, on the mobile terminal by the user, and transmitting an application authentication of the user, which is assigned to the started software application, to the application server.