Email Authentication for Passwordless Login and Secure Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing password-based security systems for online accounts are cumbersome, inefficient, and expose vendors and customers to security risks, requiring customers to remember multiple passwords and increasing the risk of compromised accounts.
Innovation Solution
A system and method that uses email authentication for secure account access, leveraging message authentication techniques and blockchain to monitor and secure transactions, allowing vendors to manage secure login and payment processing without passwords, and providing customers with secure access through email, SMS, and social media.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If password-based security systems are used for online accounts, then customer privacy and security are protected, but the system becomes cumbersome and exposes vendors to security threats
Solution Approach 1:
The patent extracts the password management burden from the customer-vendor interaction by introducing email as a separate authentication channel. The email service provider handles password-less authentication, removing the need for customers to create, remember, and manage passwords for each vendor account while maintaining security.
Solution Approach 2:
The patent introduces an email service provider as an intermediary between the customer and vendor. This intermediary handles the authentication process using email-based verification, eliminating direct password transmission and storage between customer and vendor systems while maintaining secure access control.
2Reliability
If customers are required to remember passwords for each vendor account, then secure access is maintained, but customer frustration and inefficiency increase
Solution Approach 1:
The patent makes the email address a universal authentication credential that works across multiple vendor accounts. Instead of requiring separate passwords for each vendor, the customer's email address serves as a universal identifier that can authenticate access to any vendor account through the email service provider's verification system.
Solution Approach 2:
The system enables self-service authentication where customers receive verification codes directly in their email inbox and can independently complete the login process without vendor intervention. The email service provider automatically handles verification and authentication, allowing customers to access their accounts quickly without manual password entry.
3Reliability
If vendors manage and secure customer passwords, then account security is maintained, but the burden and security risks for vendors increase
Solution Approach 1:
The patent extracts the password management function from the vendor's system entirely. Instead of vendors storing and managing customer passwords, the authentication process is moved to the email service provider, which handles verification through email-based codes. This eliminates the vendor's responsibility for secure password storage and management.
Solution Approach 2:
The email service provider acts as an intermediary that assumes the security burden of authentication. Rather than vendors directly managing customer credentials, the intermediary handles all authentication operations through email verification, reducing vendor system complexity and eliminating password storage requirements.
Data Source
AI summary
A system and method is disclosed for providing vendors an alternative to a password-based security system. The system and method also allows vendors to manage secure transactions by leveraging various message authentication techniques while allowing the vendor full control over related processes such as payment processing and fulfillment. The system and method also monitors message requests from customers for the vendor to guarantee that the communication has not been compromised. Consolidating the authentication of users to their messaging minimizes the need for each individual vendor to maintain their own password for access to a customer account. This eliminates the requirement that customers generate a password thus increasing convenience and decreasing security risks associated with the use of passwords. This decreases risk not only for customer and vendor but also decreases the risk exposure across the internet—as the system scales.


