Embedded API for Secure Authentication Data Handling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional techniques for validating user identity in interactive computing environments often compromise sensitive information during transmission and storage, making them vulnerable to unauthorized access and interception.
Innovation Solution
An embedded third-party application programming interface (API) intercepts sensitive data on a user device and transmits it via an out-of-band communication channel to an identification-and-authentication system, preventing the host computing system from receiving or storing the data, thus enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the host computing system stores or transmits sensitive information for authentication purposes, then user identity validation is enabled, but the sensitive information becomes vulnerable to compromise through malicious interference
Solution Approach 1:
The patent extracts the sensitive information handling function from the host computing system by implementing a local API on the user's device. The API intercepts sensitive data (such as biometric information or authentication credentials) before it can be transmitted to the host system, processes it locally, and only sends non-sensitive verification results to the host. This extraction eliminates the vulnerability of transmitting sensitive information over networks while maintaining authentication functionality.
Solution Approach 2:
The patent introduces an intermediary component - the embedded API - that acts as a mediator between the user's device and the host computing system. This API layer captures sensitive information locally, performs authentication processing, and communicates only authenticated status (without the actual sensitive data) to the host system. The intermediary protects the sensitive information from exposure to the host system while still enabling its functional purpose.
2Adaptability or versatility
If sensitive information is transmitted to the host computing system for verification, then authentication functionality is provided, but additional transmission points create vulnerability to interception
Solution Approach 1:
The patent removes the transmission of sensitive information from the authentication process by extracting and processing it locally on the user's device through the embedded API. Only non-sensitive authentication results are transmitted to the host system, eliminating interception vulnerabilities while preserving authentication functionality.
Solution Approach 2:
The patent changes the dimension of data transmission by shifting from transmitting sensitive information (high-risk dimension) to transmitting authentication results (low-risk dimension). This dimensional change in data classification and transmission scope maintains authentication versatility while eliminating interception vulnerabilities.
3Reliability
If the host computing system processes sensitive data for transaction validation, then transaction security is enhanced, but the system exposes sensitive data to potential unauthorized access
Solution Approach 1:
The patent extracts sensitive data processing from the host computing system and performs it locally on the user's device through the embedded API. The API handles sensitive information (such as biometric data or authentication credentials) locally and only communicates authentication outcomes to the host system, thereby enhancing transaction security while eliminating the host system's exposure to sensitive data and reducing unauthorized access risks.
Data Source
AI summary
Aspects and examples are disclosed for improving security of authentication elements for validating a user of a user device. In one example, a processor of a user device establishes a first communication channel with a host computing system, and a user interface capable of transmitting information to the host computing system via the first channel. An API on the user device establishes a second communication channel with an identification-and-authentication system. The API receives sensitive information entered in the user interface and prevents transmission of the sensitive information to the host computing systems via the first channel. The API also transmits to the identification-and-authentication system, via the second channel, a signal including the sensitive information. The identification-and-authentication system may use the signal to send to the host computing system an additional signal verifying that the user of the user device is authenticated.


