Dynamic Authentication via Short-Range Session ID Coupling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication methods, such as usernames and passwords, are prone to security weaknesses and are cumbersome, failing to concurrently authenticate identity and physical presence, and do not dynamically provision secure access rights.
Innovation Solution
A system that dynamically couples identities to secure endpoint resources by providing a unique session identifier through short-range communications, allowing authentication and authorization without requiring credentials, and granting appropriate access rights based on verified identity and proximity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If username and password authentication is used, then authentication can be obtained, but security is compromised when credentials are stolen and usability deteriorates due to password management burdens
Solution Approach 1:
The patent extracts the authentication credential from the user and stores it securely in a portable authentication device (fob). Instead of requiring users to remember and manage passwords, the authentication credential is taken out and stored in a separate secure device that can be carried by the user. This resolves the contradiction by maintaining security through secure credential storage while improving usability by eliminating password management burdens.
Solution Approach 2:
The patent introduces a portable authentication device (fob) as an intermediary between the user and the authentication system. This intermediary device securely stores authentication credentials and communicates with the authentication server, eliminating the need for users to directly handle passwords. This resolves the contradiction by maintaining security through the intermediary's secure credential management while improving usability by removing password management requirements from users.
2Reliability
If two-factor authentication is implemented, then security is enhanced, but the system cannot concurrently authenticate identity and physical presence and becomes cumbersome
Solution Approach 1:
The patent merges identity authentication and physical presence verification into a single unified authentication process. The portable authentication device contains both the user's identity information and their biometric data, allowing both authentication factors to be verified simultaneously through a single authentication operation rather than requiring separate steps. This resolves the contradiction by maintaining enhanced security through dual-factor verification while improving usability by eliminating the cumbersome sequential process.
Solution Approach 2:
The patent enables the portable authentication device to perform self-service authentication by automatically presenting both identity and biometric credentials to the authentication server without requiring user intervention to switch between different authentication methods. The device autonomously handles the complete authentication process, resolving the contradiction by maintaining security through comprehensive credential verification while improving ease of operation through automated self-service authentication.
3Adaptability or versatility
If traditional authentication methods are used, then access can be granted, but dynamic provisioning of secure access rights based on physical proximity cannot be achieved
Solution Approach 1:
The patent implements dynamic access provisioning by enabling the authentication system to adjust access rights based on the user's physical proximity to the endpoint resource. When the portable authentication device is detected near the resource, the system dynamically provisions appropriate access credentials and permissions. This resolves the contradiction by achieving adaptability through proximity-based dynamic credential issuance while maintaining reliability through secure authentication verification before granting access.
Data Source
AI summary
Disclosed embodiments relate to systems and methods for dynamically providing coupling between auxiliary computing devices and secure endpoint computing resources. Techniques include identifying a request for an identity to access an endpoint computing resource; obtaining a unique session identifier in response to the request; transmitting the unique session identifier via short-range communications from the endpoint computing resource to an auxiliary computing device associated with the identity; obtaining, in response to the auxiliary computing device transmitting the unique session identifier and the identification data, authentication data sufficient to comply with the authentication requirement of the endpoint computing resource; and dynamically coupling the identity to the endpoint computing resource based on the authentication data and consistent with the authentication requirement.


