Hardware Scan Data Authentication for Secure Identity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network identity verification methods for web services are costly and inconvenient due to the need for multiple identity verification devices and passwords, as well as duplication of investment in user identity authentication across different Internet content providers.
Innovation Solution
A network authentication method utilizing a user terminal, a downloading unit, and identity verification servers, where the user terminal downloads a scan program and asymmetrical public key, and upon login request, it connects with an identity verification server through separate communication links to verify user identity using encrypted information and hardware scan data, eliminating the need for additional authentication devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional identity verification devices (USB devices, IC cards, dynamic tokens) are provided for each user, then security of web services is improved, but cost of customer service for personalization, distribution and troubleshooting becomes considerable
Solution Approach 1:
The patent uses hardware scan data (a copy of hardware characteristics) instead of physical verification devices. The user terminal scans hardware information and transmits it to the server for verification, eliminating the need for physical USB devices, IC cards, or dynamic tokens that require costly distribution and support.
Solution Approach 2:
The patent replaces the mechanical/physical verification system (physical devices that need to be distributed, installed, and supported) with an information-based system using hardware scan data transmitted through communication networks, thereby reducing customer service costs.
2Reliability
If users need to remember user ID and password for each ICP and have different identity verification devices for different ICPs, then security for each service is maintained, but ease of operation deteriorates
Solution Approach 1:
The patent creates a universal authentication mechanism where the same user terminal and hardware scan data can be used across different ICPs. Instead of requiring separate verification devices for each service, the system uses the user's existing terminal hardware characteristics as a universal identifier, eliminating the need to manage multiple passwords and devices.
3Reliability
If different ICPs invest in user identity authentication separately, then security verification is provided, but duplication of investment occurs
Solution Approach 1:
The patent introduces an intermediary authentication mechanism where ICPs can verify user identity by checking hardware scan data against reference data stored in the user terminal. This allows ICPs to verify user identity without each one building their own complete authentication system, reducing duplication of investment while maintaining security.
Data Source
AI summary
In a network authentication method, a content-provider server redirects a user terminal to an identity verification server for acquiring therefrom an encrypted web address signed with an asymmetrical private key and downloaded from a downloading unit. The user terminal transmits hardware scan data associated therewith to the identity verification server upon determining, based on the encrypted web address and an asymmetrical public key from the downloading unit, that the identity verification server is currently valid to perform identity verification. The identity verification server verifies the identity of the user terminal based on relationship between the hardware scan data and pre-stored reference hardware scan data.


