Identity Provider Authentication Token System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Internet-centric authentication schemes face security vulnerabilities and adoption challenges due to password re-use, interception of one-time passwords, and complex enrollment processes, leading to significant security risks and costs for consumers and commercial interests.

Innovation Solution

A computer-implemented system using a single identity provider with a processor and non-transient storage media to manage authentication tokens, featuring asymmetric cryptography and pseudorandom activation codes, allowing users to securely access multiple Internet services through a device-based application, leveraging Open ID Connect protocols for secure and seamless authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional single factor username and password schemes are used, then ease of operation is improved, but security is worsened due to password interception and phishing attacks

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an identity provider as an intermediary between users and service providers. The identity provider issues authentication tokens that mediate the authentication process, replacing direct password transmission with token-based verification through a trusted third party, thereby enhancing security while maintaining ease of operation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a digital copy of the user's authentication credentials in the form of authentication tokens. Instead of repeatedly transmitting the actual password, the system generates token copies that can be used for authentication without exposing the original credentials, thus improving security while preserving operational convenience

Inventive Principle:
Principle #26Copying

2Reliability

If multi-factor authentication schemes are implemented, then security is improved, but device complexity and enrollment complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple authentication factors into a single authentication token issued by the identity provider. The token combines knowledge-based credentials with device-based identification, consolidating multiple security factors into one unified mechanism that reduces system complexity while maintaining enhanced security

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication token serves multiple functions: it authenticates the user's identity, verifies device ownership, and enables access to multiple services. This multi-functional approach eliminates the need for separate authentication mechanisms for different factors, reducing overall system complexity while providing robust security

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If hardware tokens are used for multi-factor authentication, then security is improved, but ease of operation is worsened due to the need to manage multiple physical tokens

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical hardware token system with a software-based authentication token stored on the user's device. This substitution eliminates the need for physical tokens and their associated management overhead, while maintaining the security benefits of multi-factor authentication through digital credential verification

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If distinct software-based tokens are required for each service, then security is improved, but device complexity and time consumption increase

Engineering Contradiction:
ImprovesecurityVSAvoidenrollment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates a universal authentication token that can be used across multiple services and providers. The single token issued by the identity provider serves all authentication needs, eliminating the requirement to enroll and manage separate tokens for each service, thereby reducing enrollment time and device complexity while maintaining security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10348715B2Computer-implemented systems and methods of device based, internet-centric, authentication
Publication Date: 2019.07.09 PRIVAKEY INC
  • US10348715B2 patent drawing
  • US10348715B2 patent drawing
  • US10348715B2 patent drawing

AI summary

Systems and computer-implemented methods for authorizing respective access by each of a plurality of Internet users to a respective one or more Internet services provided by each of a plurality of Internet service providers. A system includes a processor, and non-transient computer readable storage media, at a single identity provider. The storage media is encoded with program code executable by the processor for requiring an identity provider application residing on each of a plurality of devices to create a respective authentication token that is specific to a respective identifier and user credential of a respective Internet user, a respective device identifier, and the respective identity provider application, and for authorizing respective access by the plurality of Internet users to a respective requested one of the Internet services provided by each Internet service provider using the respective created authentication tokens and respective identifiers for each of the respective requested Internet services.