Credential Provision and Proof System via Distinct Channels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network client authentication methods are inadequate when the credential reader is not embedded within or directly accessible to the communication device, limiting transaction completion if the credential reader is not present or accessible.

Innovation Solution

A credential provision and proof system that authenticates clients using an authentication token, where a computer server receives the token from a first authentication client via a first communications channel, determines its authenticity, and transmits a payload to a second authentication client via a distinct second communications channel, enabling transaction completion with a relying party server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a credential reader is not embedded within or directly accessible to a communication device, then the system gains flexibility in authentication methods, but the ability to complete transactions is limited

Engineering Contradiction:
Improveflexibility in authentication methodsVSAvoidability to complete transactions
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a server as an intermediary component that receives authentication tokens from communication devices and validates credentials separately. This mediator architecture allows the credential verification process to be decoupled from the communication device, enabling transaction completion even when the credential reader is not embedded within the device itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If authentication is performed through a separate server rather than embedded credential reader, then system flexibility improves, but communication channel complexity increases

Engineering Contradiction:
Improveauthentication architecture flexibilityVSAvoidcommunication channel structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into distinct communication channels: one channel for transmitting the authentication token from the communication device to the server, and another channel for the server to communicate with the credential reader. This segmentation allows each channel to be optimized independently and simplifies the overall architecture by separating concerns.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2556624B1Credential provision and proof system
Publication Date: 2020.02.26 SECUREKEY TECH
  • EP2556624B1 patent drawingFigure 1
  • EP2556624B1 patent drawingFigure 2
  • EP2556624B1 patent drawingFigure 3

AI summary

A method of authenticating to a computer server involves a first authentication client transmitting an authentication token to the computer server via a first communications channel, and a second authentication client receiving a payload from the computer server via a second communications channel distinct from the first communications channel in accordance with an outcome of a determination of authenticity of the authentication token by the computer server.