Dual-Channel Authentication Server Process for Secure User Convenience

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods in distributed computer systems often compromise between security and user convenience, particularly when manual entry of codes from mobile devices is required, leading to user frustration and potential errors.

Innovation Solution

A method involving multiple communication layers, including primary and secondary authentication communications, where the server initiates and processes authentication information without requiring users to manually input data from the client device, utilizing push notifications and device-specific identification for secure and convenient dual-factor authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual code entry from mobile device is required for authentication, then security is improved, but user convenience deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs automatic authentication where the client process automatically sends authentication codes to the server process without requiring manual user intervention. The user simply needs to provide credentials once during setup, and the system handles subsequent authentications automatically, eliminating the need for manual code entry while maintaining security through device-specific identification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where a client process acts as a mediator between the user and the server. This intermediary automatically manages authentication codes and communicates with the server process, bridging the gap between security requirements and user convenience by handling the complex authentication流程 in the background.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple authentication communications are implemented, then authentication security is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into distinct communication channels: a primary authentication communication for initial credential verification and a secondary authentication communication for automatic code transmission. This segmentation allows each communication path to be optimized independently, maintaining security through multiple layers while managing complexity by clearly defining the role of each communication channel.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If automatic authentication is implemented, then user convenience is improved, but potential errors increase

Engineering Contradiction:
Improveuser convenienceVSAvoidauthentication accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary registration where device-specific identification is captured and stored during an initial setup phase. This preliminary action creates a reliable reference baseline that enables subsequent automatic authentications to proceed accurately without manual intervention, reducing errors by having pre-validated device information available for comparison during automatic authentication processes.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11159522B2Method for authentication, server, device and data carrier
Publication Date: 2021.10.26 BASELINE AUTOMATISERING
  • US11159522B2 patent drawing
  • US11159522B2 patent drawing
  • US11159522B2 patent drawing

AI summary

A method for authentication between a server process and a client process by means of multiple communication including a primary authentication communication and a secondary authentication communication. The method includes steps for: the server process receiving from the client process an initiating communication of the primary authentication communication, the server process initiating the secondary authentication communication between the server process and a client authentication process, the server process receiving primary authentication information comprising an authentication code or an authentication result, the server process receiving secondary authentication information comprising an authentication code or an authentication result of the secondary authentication communication, and the server process establishing the authentication on the basis of the primary and secondary authentication information.