Client Identifier Authentication via Distributed Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The traditional username and password approach for user authentication on secure servers is vulnerable to security flaws, including theft and alteration, and requires interactive self-authentication, which can be compromised by malicious parties.

Innovation Solution

A system and method for streamlined user authentication using a securely stored client identifier parameter, which is immutably stored in a distributed data storage system and accessed automatically for initiating an interactive communication session without user interaction, ensuring secure and seamless authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If username and password approach is used for user authentication, then user identity can be proven to access restricted functions, but security vulnerabilities arise including theft and alteration of credentials

Engineering Contradiction:
Improveauthentication securityVSAvoidtheft and alteration of credentials
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication credential (client identifier parameter) from the traditional username-password system and stores it separately in a distributed data storage system. The credential is divided into two parts: one stored on the client device and one on the authentication server, neither of which contains the complete authentication information alone. This extraction and distribution approach eliminates the security vulnerability of centralized credential storage that is susceptible to theft and alteration.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication system is segmented into multiple components: the client device, the authentication server, and the distributed data storage system. The client identifier parameter is further segmented into two separate storage locations, so that no single entity possesses the complete credential. This segmentation ensures that even if one part is compromised, the authentication security remains intact.

Inventive Principle:
Principle #1Segmentation

2Reliability

If interactive self-authentication is required from users, then user identity verification can be performed, but the process is time-consuming and vulnerable to malicious interference

Engineering Contradiction:
Improveidentity verificationVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The client identifier parameter is pre-stored in the distributed data storage system before the authentication process begins. When authentication is needed, the system simply retrieves and compares the pre-stored parameter with the one presented by the client device, eliminating the need for interactive user input. This preliminary storage of authentication credentials enables rapid, automated authentication without user interaction.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system operates autonomously without requiring user interaction. The client device automatically presents its client identifier parameter, and the authentication server automatically retrieves and verifies the corresponding parameter from the distributed storage system. The entire authentication process is self-service, eliminating time loss due to user input and reducing vulnerability to malicious interference through automated verification.

Inventive Principle:
Principle #25Self-service

3Reliability

If client identifier parameter is securely stored in distributed data storage system, then security is enhanced, but system complexity increases

Engineering Contradiction:
Improvecredential securityVSAvoidstorage system architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The distributed data storage system serves multiple functions: it stores the authentication credentials securely, enables automated retrieval during authentication, and provides a decentralized structure that enhances security. By making the storage system multi-functional, the patent reduces the need for separate security mechanisms, thereby managing complexity while enhancing credential security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11245690B1System and method for streamlined user authentication on a server using a securely stored client identifier
Publication Date: 2022.02.08 DG VENTURES LLC
  • US11245690B1 patent drawing
  • US11245690B1 patent drawing
  • US11245690B1 patent drawing

AI summary

A system and method provide streamlined restricted access to a secure server through a communications network. A client identifier parameter value is established and uniquely associated with a user registering with an authentication server, and is stored in at least first and second predetermined storage forms within a data storage system, the first form readable exclusively by a client device of the user and the second form readable by the authentication server. The client device then authenticates by retrieving the client identifier parameter value from the data storage system and providing it to the authentication server, which independently retrieves the client identifier parameter value from the data storage system for comparison, and initiates an interactive communication session between the client device and the secure server responsive to the comparison. Between comparisons, the client identifier parameter values are stored exclusively on the data storage system and deleted from all other devices.