Identity Provider Authentication Token System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Internet-centric authentication schemes face security vulnerabilities and adoption challenges due to password re-use, interception of one-time passwords, and complex enrollment processes, leading to significant security risks and costs for consumers and commercial interests.
Innovation Solution
A computer-implemented system using a single identity provider with a processor and non-transient storage media to manage authentication tokens, featuring asymmetric cryptography and pseudorandom activation codes, allowing users to securely access multiple Internet services through a device-based application, leveraging Open ID Connect protocols for secure and seamless authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional single factor username and password schemes are used, then ease of operation is improved, but security is worsened due to password interception and phishing attacks
Solution Approach 1:
The patent introduces an identity provider as an intermediary between users and service providers. The identity provider issues authentication tokens that mediate the authentication process, replacing direct password transmission with token-based verification through a trusted third party, thereby enhancing security while maintaining ease of operation
Solution Approach 2:
The patent creates a digital copy of the user's authentication credentials in the form of authentication tokens. Instead of repeatedly transmitting the actual password, the system generates token copies that can be used for authentication without exposing the original credentials, thus improving security while preserving operational convenience
2Reliability
If multi-factor authentication schemes are implemented, then security is improved, but device complexity and enrollment complexity increase
Solution Approach 1:
The patent merges multiple authentication factors into a single authentication token issued by the identity provider. The token combines knowledge-based credentials with device-based identification, consolidating multiple security factors into one unified mechanism that reduces system complexity while maintaining enhanced security
Solution Approach 2:
The authentication token serves multiple functions: it authenticates the user's identity, verifies device ownership, and enables access to multiple services. This multi-functional approach eliminates the need for separate authentication mechanisms for different factors, reducing overall system complexity while providing robust security
3Reliability
If hardware tokens are used for multi-factor authentication, then security is improved, but ease of operation is worsened due to the need to manage multiple physical tokens
Solution Approach 1:
The patent replaces the mechanical hardware token system with a software-based authentication token stored on the user's device. This substitution eliminates the need for physical tokens and their associated management overhead, while maintaining the security benefits of multi-factor authentication through digital credential verification
4Reliability
If distinct software-based tokens are required for each service, then security is improved, but device complexity and time consumption increase
Solution Approach 1:
The patent creates a universal authentication token that can be used across multiple services and providers. The single token issued by the identity provider serves all authentication needs, eliminating the requirement to enroll and manage separate tokens for each service, thereby reducing enrollment time and device complexity while maintaining security
Data Source
AI summary
Systems and computer-implemented methods for authorizing respective access by each of a plurality of Internet users to a respective one or more Internet services provided by each of a plurality of Internet service providers. A system includes a processor, and non-transient computer readable storage media, at a single identity provider. The storage media is encoded with program code executable by the processor for requiring an identity provider application residing on each of a plurality of devices to create a respective authentication token that is specific to a respective identifier and user credential of a respective Internet user, a respective device identifier, and the respective identity provider application, and for authorizing respective access by the plurality of Internet users to a respective requested one of the Internet services provided by each Internet service provider using the respective created authentication tokens and respective identifiers for each of the respective requested Internet services.


