Credential Provision and Proof System via Distinct Channels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network client authentication methods are inadequate when the credential reader is not embedded within or directly accessible to the communication device, limiting transaction completion if the credential reader is not present or accessible.
Innovation Solution
A credential provision and proof system that authenticates clients using an authentication token, where a computer server receives the token from a first authentication client via a first communications channel, determines its authenticity, and transmits a payload to a second authentication client via a distinct second communications channel, enabling transaction completion with a relying party server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a credential reader is not embedded within or directly accessible to a communication device, then the system gains flexibility in authentication methods, but the ability to complete transactions is limited
Solution Approach 1:
The patent introduces a server as an intermediary component that receives authentication tokens from communication devices and validates credentials separately. This mediator architecture allows the credential verification process to be decoupled from the communication device, enabling transaction completion even when the credential reader is not embedded within the device itself.
2Adaptability or versatility
If authentication is performed through a separate server rather than embedded credential reader, then system flexibility improves, but communication channel complexity increases
Solution Approach 1:
The patent segments the authentication process into distinct communication channels: one channel for transmitting the authentication token from the communication device to the server, and another channel for the server to communicate with the credential reader. This segmentation allows each channel to be optimized independently and simplifies the overall architecture by separating concerns.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method of authenticating to a computer server involves a first authentication client transmitting an authentication token to the computer server via a first communications channel, and a second authentication client receiving a payload from the computer server via a second communications channel distinct from the first communications channel in accordance with an outcome of a determination of authenticity of the authentication token by the computer server.