Certified Approval Service Decouples Authentication from User Login

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Login-based approval mechanisms are inflexible and vulnerable to data theft, leading to security issues and increased complexity, particularly in scenarios involving multiple users and sensitive transactions.

Innovation Solution

The Certified Approval Service (CAS) decouples approvals from user login identities, using deep encryption and secure communication protocols between CAS devices and providers to facilitate secure transactions without the need for user login sessions, enabling convenient and secure approvals for various services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If login-based approval mechanisms are used, then user authentication and service access control are achieved, but security vulnerabilities and data theft risks increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiddata theft risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication credential (certificate) from the user's direct possession and places it in a secure element or hardware module. The certificate is stored in a protected environment isolated from the main system, preventing direct access by malware or unauthorized processes while still enabling authentication functions.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a certificate authority and a secure element as intermediaries between the user and the service provider. The certificate authority issues and manages certificates, while the secure element acts as a mediator that holds and protects the private key, eliminating the need for users to directly manage sensitive authentication data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If login-based approval mechanisms are used, then service access control is implemented, but system complexity increases

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses certificate copies distributed to multiple service providers. Instead of requiring complex centralized authentication systems, each service provider receives a copy of the user's certificate, enabling independent verification. This simplifies the overall system architecture by replacing complex centralized control with simpler distributed verification.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent creates a universal certificate format that can be used across multiple services and platforms. The same certificate structure and verification mechanism work for different service providers, eliminating the need for service-specific authentication systems and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If user passwords and authentication data are stored, then user authentication is enabled, but security vulnerabilities and attack surfaces increase

Engineering Contradiction:
Improveauthentication convenienceVSAvoidauthentication data theft
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authentication system into separate functional components: certificate storage in a secure element, authentication logic in the service provider, and verification processes isolated from user-facing applications. This segmentation ensures that even if one component is compromised, the others remain protected.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates an inert security environment using hardware-based secure elements that are resistant to software attacks. The private key and sensitive authentication data are stored in this protected environment that is isolated from the volatile software layer, making it inaccessible to malware and unauthorized processes while still enabling authentication operations.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

Data Source

PatentUS11570167B1Method and apparatus for one or more certified approval services
Publication Date: 2023.01.31 CHIPIWORKS CO
  • US11570167B1 patent drawing
  • US11570167B1 patent drawing
  • US11570167B1 patent drawing

AI summary

Apparatus and methods pertaining to a Certified Approval Service (CAS) are disclosed and enabled. The apparatus may include a Personal Computing Device (PCD) implementing a CAS Device to interact with an end user and a server implementing a CAS provider. The various embodiments operate without the end user and the CAS provider to engage in an authenticated login session between themselves.