Identity Module Authentication via Unique Token
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication mechanisms for mobile and non-mobile computing devices fail to securely manage user accounts across multiple applications, often sharing sensitive user data and compromising privacy.
Innovation Solution
A method and system that uses an authorization module to communicate with a remote identity module, providing a unique token for authentication without sharing secure user data, allowing applications to sign into user accounts while maintaining privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional authentication mechanisms are used to enable applications to access user accounts, then application functionality is improved, but user data privacy and security are compromised due to sharing of sensitive user data
Solution Approach 1:
The patent introduces an identity module as an intermediary between applications and user accounts. This identity module acts as a mediator that handles authentication and authorization requests, allowing applications to access user accounts without directly sharing or exposing sensitive user data. The identity module verifies application credentials and manages the authentication process, ensuring that user data remains protected while still enabling application functionality.
Solution Approach 2:
The patent segments the authentication system into distinct components: applications, authorization modules, identity modules, and user accounts. Each component has a specific role and operates independently. The identity module is separated from both the application logic and the user data storage, creating a layered architecture where sensitive data is isolated. This segmentation allows applications to function without direct access to user data, maintaining security while enabling versatility.
2Reliability
If verification codes are transmitted to client devices for authentication, then authentication security is improved, but communication complexity increases due to multiple message transmissions
Solution Approach 1:
The client device's authorization module performs self-service by automatically generating, transmitting, and verifying authentication credentials without requiring manual user intervention for each step. The module handles the entire verification code transmission and confirmation process autonomously, reducing the perceived complexity for users while maintaining robust security protocols. The system serves itself by managing the authentication workflow internally.
Data Source
AI summary
A system and method including: receiving an authorization request originating from an authorization module of an application executing on a client device, where the authorization request includes an identifier identifying the client device; causing transmission, based on the identifier, of a verification message to the client device, where the verification message includes a verification code; receiving a confirmation of the verification code from the authorization module of the application executing on the client device; authenticating the application based on the receiving the confirmation of the verification code; determining that the client device identified by the identifier corresponds to a user account including secure user data associated with a user; and transmitting a unique token verifying that the application is authorized to sign into the user account, where: the unique token uniquely identifies the user account to the application, and the secure user data is not shared with the application.


