Credential Host for Secure Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Local computers are vulnerable to malware attacks that capture and transmit user credentials and private information, leading to unauthorized access and financial loss, as existing security measures are often ineffective in preventing such breaches, especially on unsecured or public computers.

Innovation Solution

A host-based security system that stores user credentials in a credential host, which transmits them securely over the network for authentication, minimizing the risk of capture by malware on the local computer, and optionally uses an auxiliary device for additional authentication and data protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If credentials are stored and transmitted from a local computer, then authentication can be performed, but the local computer becomes vulnerable to malware attacks that capture and misappropriate credentials

Engineering Contradiction:
Improveauthentication securityVSAvoidmalware attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the credential storage and transmission function from the local computer and relocates it to a remote credential host. The local computer only receives authentication challenges and sends responses, while all sensitive credential data resides and is managed on the secure remote server, eliminating the attack surface for credential theft at the local device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a credential host as an intermediary between the local computer and destination sites. This mediator manages credential storage, generates authentication challenges, and handles credential transmission securely, preventing direct exposure of credentials on the local computer while maintaining authentication functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security software is installed on local computers, then some protection is provided, but users may fail to properly configure or update the software, leaving vulnerabilities

Engineering Contradiction:
Improvesecurity protectionVSAvoidconfiguration and maintenance complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service security by moving credential management to a remote host that automatically handles security updates, configuration, and credential protection without requiring user intervention. The local computer simply interacts with the secure remote system, eliminating the need for users to configure or maintain security software locally.

Inventive Principle:
Principle #25Self-service

3Reliability

If credentials are transmitted over the network, then authentication is enabled, but transmission may be intercepted or misappropriated by unauthorized parties

Engineering Contradiction:
Improveauthentication functionalityVSAvoidcredential interception risk
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent performs preliminary authentication by having the credential host generate authentication challenges and prepare credential responses before actual network transmission to destination sites. This pre-authentication process ensures that only verified credentials are transmitted, and the remote host maintains control over the entire credential lifecycle, minimizing exposure during network communication.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9246901B2Secure network computing
Publication Date: 2016.01.26 PERSONAL CAPITAL TECH COPORATION
  • US9246901B2 patent drawing
  • US9246901B2 patent drawing
  • US9246901B2 patent drawing

AI summary

A host based security system for a computer network includes in communication with the network a credential host that is operative in concert with a local computer and a destination site. The destination site has a credential authentication policy under which credentials associated with the local computer upon being authenticated authorizes data to be communicated between each of the destination site and the local computer during a communication session over the network. The credential host stores the credentials to be used by the destination and is operative to transmit the credentials onto the network in response to a request received from the local computer. The destination site upon the credentials being received and authenticated thereat is operative to transmit session information onto the network. The local computer is then operative to commence the communication session upon receipt of said the information.