Composite Hash Authentication for Network Credential Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for accessing network services face security risks due to vulnerabilities in public or private key encryption, allowing malicious entities to intercept user credentials, and lack a secure mechanism for sharing credentials, leading to potential unauthorized access.
Innovation Solution
Generating a cryptographic composite hash of user-specific information and creating a graphical representation, such as a QR code, which is stored on a local auxiliary device, allowing secure sharing and local authentication without transmitting sensitive information over networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If public or private key encryption algorithms are used to protect user credentials during transmission, then credential security is improved, but malicious entities can still intercept sensitive information through man-in-the-middle attacks or key theft
Solution Approach 1:
The patent extracts the sensitive credential information from the transmission process by using hashing functions to convert credentials into composite hashes. The original credentials are never transmitted over the network, only the hashed composite hash is transmitted, eliminating the risk of credential interception while maintaining authentication capability
Solution Approach 2:
The patent introduces composite hashes as an intermediary between user credentials and authentication verification. Instead of transmitting actual credentials, the system transmits composite hashes that serve as secure representatives, preventing direct exposure of sensitive information while enabling authentication
2Ease of operation
If user credentials are shared via traditional methods (pen and paper, email, text messages), then credential sharing is enabled, but malicious entities can obtain user credentials through these communication channels
Solution Approach 1:
The patent creates graphical representations (QR codes, barcodes, images) as visual copies of composite hashes that can be easily shared and scanned. These graphical copies replace traditional sharing methods, maintaining ease of credential sharing while ensuring that only the hashed composite hash is transmitted, not the actual credentials
Solution Approach 2:
The patent replaces manual credential sharing methods (writing, typing, speaking credentials) with graphical representation scanning. Users simply scan a QR code or image with their device, eliminating the need to manually transmit credentials through vulnerable communication channels
3Adaptability or versatility
If composite hashes are transmitted over computing networks for authentication, then network access is enabled, but network traffic increases and potential interception points are created
Solution Approach 1:
The patent performs preliminary hashing of credentials to create composite hashes before transmission. This preprocessing step ensures that only compact, fixed-length hash values are transmitted over the network rather than potentially large credential strings, reducing network traffic while maintaining authentication functionality
Data Source
AI summary
In some embodiments, increasing network security related to accessing network services may be facilitated. In some embodiments, a request to generate a composite hash with composite hash parameters may be received, where the composite hash parameters comprise (i) user information associated with a first user and (ii) a key. Based on the one or more composite hash parameters, a composite hash may be generated. The composite hash may be transmitted to a local auxiliary device, causing storage of the composite hash at the local auxiliary device. A graphical representation of the composite hash may be generated, and the graphical representation may be transmitted to a user device, where the graphical representation enables access to one or more network resources related to the user information associated with the first user.


