Global Authentication Service Using QR Code and Mobile Device

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The inefficiency of relying on usernames and passwords for user authentication, which can lead to security issues due to the need for multiple credentials, forgetfulness, and vulnerability to hacking or theft.

Innovation Solution

A global authentication service that uses a mobile device to authenticate users through a QR code and global user identifier, eliminating the need for traditional usernames and passwords by linking a mobile device to third-party services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional username and password authentication is used, then users can access services, but security risks increase due to multiple credentials being vulnerable to hacking or theft

Engineering Contradiction:
Improveauthentication securityVSAvoidvulnerability to hacking or theft
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication credential from the user's direct control and stores it securely on the service provider's server. The credential is generated by the service provider and stored in an encrypted form, eliminating the need for users to manage sensitive authentication data that could be compromised.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a credential as an intermediary between the user and the service. Instead of directly sharing passwords, the system uses a credential that the user provides to access services. This credential acts as a secure mediator that can be revoked and replaced without affecting the user's master password.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If users create separate usernames and passwords for each service, then security isolation is achieved, but user burden increases due to remembering multiple credentials

Engineering Contradiction:
Improvesecurity isolationVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a universal credential system where a single credential generated by one service provider can be used across multiple services. The credential contains universal identifiers that allow it to function across different service platforms, eliminating the need for users to remember multiple separate passwords while maintaining security isolation through the underlying architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If centralized authentication is implemented, then user convenience improves, but system complexity increases

Engineering Contradiction:
Improveauthentication simplicityVSAvoidsystem architecture complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent performs preliminary authentication and credential generation during the initial service setup. The credential is created in advance with embedded service identifiers and authentication data, so that subsequent service accesses can proceed without complex real-time authentication negotiations, simplifying the user experience while managing system complexity through pre-computation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9529985B2Global authentication service using a global user identifier
Publication Date: 2016.12.27 VERIZON PATENT & LICENSING INC
  • US9529985B2 patent drawing
  • US9529985B2 patent drawing
  • US9529985B2 patent drawing

AI summary

An authentication device may provide an authentication code to a third party device. The third party device may provide a third party service to which a client device has requested access. The authentication device may receive the authentication code from a mobile device that is different from the client device. The authentication device may determine a third party device identifier included in the authentication code. The third party device identifier may identify the third party device that provides the third party service. The authentication device may determine a transaction identifier included in the authentication code. The authentication device may selectively provide the transaction identifier to the third party device, identified by the third party device identifier, to cause the third party device to selectively permit the client device to access the third party service.