Client Authentication Using Dynamic Policy-Based Encoded Passcodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods such as password-based, multi-factor, certificate-based, and token-based systems are vulnerable to phishing, device loss, key theft, and high costs, respectively, necessitating a more secure and dynamic approach.

Innovation Solution

A policy-based authentication method using a Regulated Activation Network (RAN) model generates a hierarchical passcode structure, where each authentication attempt uses a unique encoded passcode, ensuring randomness and security through computational modeling and dynamic policy generation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If password-based authentication is used, then implementation is simple, but it is vulnerable to phishing attacks and password guessing

Engineering Contradiction:
Improveimplementation simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces a biometric template as an intermediary between the user and the authentication system. Instead of directly using passwords or biometric data, the system uses a transformed biometric template that cannot be reverse-engineered to obtain the original biometric data or password, thus providing security while maintaining usability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional password-based mechanical authentication with a biometric-based authentication system. The biometric template transformation mechanism substitutes the need for users to remember and input passwords, while the transformed template provides cryptographic security against phishing and guessing attacks

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If multi-factor authentication is used, then security is improved, but it is prone to situations when devices are lost or unavailable

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a universal authentication system where a single biometric template can serve multiple authentication purposes. The transformed biometric template can be used across different devices and contexts without requiring multiple separate authentication mechanisms, thus maintaining security while improving device availability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables self-service authentication through biometric data that users inherently possess. The biometric template transformation allows the system to verify user identity using the user's own biometric characteristics, eliminating the need for external devices that could be lost or unavailable

Inventive Principle:
Principle #25Self-service

3Reliability

If certificate-based authentication is used, then security is enhanced, but it is vulnerable to the theft of private keys

Engineering Contradiction:
Improveauthentication securityVSAvoidprivate key theft vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the essential security function from traditional certificate-based authentication by using biometric templates instead of private keys. The transformed biometric template provides the same cryptographic security function without the vulnerability of private key storage and management

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system uses transformed biometric templates that can be easily regenerated and updated. Unlike private keys that must be securely stored for long periods, the biometric template can be transformed into different forms and is inherently tied to the user's living biometric data, reducing the impact of potential compromises

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

4Reliability

If token-based authentication is used, then security can be very high, but it is expensive when generating secure tokens and problematic when leaked

Engineering Contradiction:
Improveauthentication securityVSAvoidtoken generation cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent creates a copy of the biometric data in the form of a transformed template that serves the same authentication purpose as expensive secure tokens. The transformed biometric template can be transmitted and stored without the high generation costs associated with cryptographic tokens, while providing comparable security

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system uses transformed biometric templates that are computationally inexpensive to generate compared to secure tokens. These templates can be rapidly regenerated if compromised, unlike expensive tokens that require complex cryptographic operations to replace

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS12495038B2Method of authenticating a client in a client-server architecture
Publication Date: 2025.12.09 UNIVE DE COIMBRA
  • US12495038B2 patent drawing
  • US12495038B2 patent drawing
  • US12495038B2 patent drawing

AI summary

The present invention relates to a method for authenticating a Client in a Client-Server architecture. The method encodes the Client's input passcode using a Regulated Activation Network computational model to create a Hierarchical model. Depending upon a Policy shared between the Client and the Server, different combinations of encoded passcodes generated from the Hierarchical model, are selected. After every successful authentication operation, a new policy is generated. Because of these new policies, for every authentication attempt, the Client inputs the same passcode but the passcode communicated over the network is always different. The advantages of this method include random encoded passcode generation for the Client's identity verification. This randomness ensures that the generated encoded passcodes are never repeated in two successive authentication attempts. The use of Models, Policies, and the Client's passcode together makes the authentication method highly robust.