Gateway Server Mediator for Multi-Device Password Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Joint or group accounts are vulnerable to unauthorized access and data breaches when users input credentials on insecure devices, and existing methods fail to prevent hacking or identify malicious websites.

Innovation Solution

A system where a gateway server acts as an intermediary, combining partial passwords from multiple trusted mobile devices to authenticate users, thereby preventing sensitive information from being input directly on untrusted devices and ensuring only verified, trustworthy devices access the account.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users input credentials directly on client devices, then ease of operation is improved, but security against hacking and data theft deteriorates

Engineering Contradiction:
Improveease of loginVSAvoidvulnerability to hacking
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway server as an intermediary between the client device and the authentication process. The gateway server receives authentication requests, obtains credentials from mobile devices through QR code scanning, verifies them, and then allows access to the client device. This mediator prevents direct credential input on potentially compromised client devices while maintaining ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into distinct components: the client device that provides access, mobile devices that store credentials, and a gateway server that coordinates authentication. Credentials are further segmented into parts stored separately on different mobile devices, requiring multiple devices to work together for successful authentication.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a gateway server is introduced to improve security, then security against hacking is improved, but device complexity increases

Engineering Contradiction:
Improveaccount securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway server acts as a centralized intermediary that manages the complex authentication coordination between multiple mobile devices and client devices. By concentrating the coordination logic in a single server, the complexity of managing multi-device authentication is reduced while maintaining high security through the intermediary's verification processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10445487B2Methods and apparatus for authentication of joint account login
Publication Date: 2019.10.15 SINGOU TECH MACAU LTD
  • US10445487B2 patent drawing
  • US10445487B2 patent drawing
  • US10445487B2 patent drawing

AI summary

A method improves authentication of a user to login with a client device to a computer system. A mobile device reads an authentication code displayed on a display of the client device to extract a URL and a first session identifier (ID), searches a first account profile that includes a username and a first part password associated with the URL, transmits the first session ID and the first account profile to the gateway server, prompts a second mobile device to provide a second part password associated with the username to the gateway server to form a complete password, and authenticates the user to login to the computer system with the client device when the client device retrieves from the gateway server the username and the complete password.