Dynamic Authentication System Using Two-Pass Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current online authentication systems are vulnerable to fraud and security breaches due to the reliance on easily guessable passwords and lack of robust authentication mechanisms, leading to billions of dollars in lost revenue and compromised user data, as businesses hesitate to adopt stronger authentication methods due to high upfront costs and complexity.

Innovation Solution

A dynamic authentication system that provides centralized, non-federated, proxied authentication, utilizing a two-pass process to dynamically select authentication methods based on user behavior, time, and resource sensitivity, allowing users to manage authentication tokens across multiple accounts with enhanced security features like hardware tokens and real-time alerts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If websites implement stronger authentication mechanisms, then security is improved, but device complexity and upfront costs increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a third-party authentication service as an intermediary between users and websites. This service handles the complex authentication processes centrally, allowing individual websites to adopt strong authentication without bearing the full complexity burden. The intermediary manages token generation, verification, and coordination across multiple sites, reducing the authentication system complexity at each individual website while maintaining high security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication service is designed to be universal and multi-functional, serving multiple websites and users through a single platform. It provides various authentication methods (passwords, hardware tokens, software tokens) and can adapt to different security requirements. This universality allows the system to achieve high reliability across diverse applications without requiring each website to develop and maintain separate complex authentication systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If users manage multiple passwords for different sites, then authentication security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidpassword management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the authentication management function into a single centralized service that users interact with once. Instead of managing separate passwords for each website, users authenticate through a unified system that handles multiple sites. The service combines password management, token generation, and verification into one interface, significantly improving ease of operation while maintaining security through the use of multiple authentication factors when needed.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication service provides self-service capabilities where users can manage their own authentication credentials, view security status, and control their authentication methods without requiring assistance from individual websites. The system automatically generates tokens, verifies credentials, and coordinates authentication across multiple sites, reducing the operational burden on users while maintaining strong security practices.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If users use easy-to-remember passwords, then ease of operation is improved, but reliability deteriorates

Engineering Contradiction:
Improvepassword memorabilityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the authentication parameters from simple passwords to multi-factor authentication including hardware tokens and software tokens. Users can still remember a single password easily, but the system enhances security by adding additional authentication factors that do not rely on memorability. The service dynamically adjusts authentication parameters based on risk assessment, using stronger methods when needed while maintaining ease of operation for low-risk scenarios.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The centralized authentication service acts as an intermediary that manages the transition from simple passwords to more secure authentication methods. It handles the complexity of multi-factor authentication while presenting a simple interface to users. The service can issue hardware tokens or software tokens that work with easy-to-remember passwords, combining the ease of operation with improved reliability through the intermediary's coordination of multiple authentication factors.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If websites implement centralized authentication, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized authentication service as an intermediary that assumes the complexity burden. Individual websites do not need to implement their own complex authentication infrastructure; instead, they integrate with the centralized service through standardized interfaces. The intermediary manages user credentials, generates authentication tokens, and coordinates verification across all participating websites, thereby improving reliability while preventing the proliferation of complex authentication systems at each individual site.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into distinct functional components: user registration, credential storage, token generation, verification, and session management. The centralized service handles the complex segments (credential storage, token generation), while websites only need to implement simple integration segments (authentication requests and responses). This segmentation allows the system to achieve high reliability through centralized management without imposing full complexity on individual websites.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8756661B2Dynamic user authentication for access to online services
Publication Date: 2014.06.17 LEVENBERG CORY
  • US8756661B2 patent drawing
  • US8756661B2 patent drawing
  • US8756661B2 patent drawing

AI summary

A dynamic authentication system that makes authentication stronger, while reducing the cost to business and the burden to users. The system includes a service that provides centralized, non-federated, proxied authentication. The system uses a two-pass authentication process that first receives a supposed identity of the user and then determines one or more authentication criteria for proving that supposed identity. When the user attempts to use an online service that relies on the dynamic authentication system for authentication, the service requests the user's identity. The system dynamically determines authentication criteria for the user to prove the provided identity belongs to the user. In the second pass, the service receives a response from the user containing additional authentication information, and forwards the received response to the system for verification. If verification succeeds, the service allows the user to access the requested resources.