Integrated Cybersecurity System for Isolated Client Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security techniques for protecting data in the information age rely heavily on passwords, which are vulnerable to breaches and require users to store sensitive information, posing risks for both users and third-party sites.

Innovation Solution

An integrated cybersecurity method that uses a unique identifier issued to a client, verified locally through biometric means, and encrypted before being sent to a server for authentication, allowing for secure access to websites without storing user information on third-party sites, thus isolating user data and reducing liability in case of a breach.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional password-based authentication is used, then users can access protected information, but user data is vulnerable to breaches and requires users to store sensitive information

Engineering Contradiction:
Improveauthentication securityVSAvoiddata breach risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication verification process from the third-party website and relocates it to a dedicated authentication server. The website only receives authentication results, not user credentials. This extraction eliminates the website's exposure to sensitive user data while maintaining authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary authentication server that mediates between the user and the third-party website. This intermediary handles all authentication operations using stored credentials, preventing direct exposure of user data to websites while enabling secure access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If users store passwords on third-party sites, then access is granted, but liability and security risks increase for both users and sites

Engineering Contradiction:
Improveaccess managementVSAvoidsecurity infrastructure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent creates a universal authentication server that serves multiple third-party websites with a single credential set. This multi-functional system allows users to access different websites without storing credentials on each site, reducing the security infrastructure complexity at individual websites while maintaining ease of access.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Speed

If biometric verification is performed locally without server interaction, then authentication speed improves, but verification security may be compromised

Engineering Contradiction:
Improveauthentication speedVSAvoidverification accuracy
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent performs preliminary biometric verification locally on the user's device before server communication occurs. This preliminary action captures the biometric data and compares it against stored templates locally, providing rapid initial authentication while the server subsequently validates the authentication result, thus maintaining both speed and reliability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11968196B2Integrated cybersecurity system and method for providing restricted client access to a website
Publication Date: 2024.04.23 SOFTEX INC
  • US11968196B2 patent drawing
  • US11968196B2 patent drawing
  • US11968196B2 patent drawing

AI summary

Integrated cybersecurity systems and method for providing client access to a website. The methods involve receiving website configuration information for the client access; receiving client enrollment data for the client access; receiving client input data from a client; defining integrated client confirmation; and providing the website with the client identification information based on the integrated client confirmation. The defining involves authenticating the client input data by comparing the client input data with the client enrollment data; authorizing the authenticated client by determining client authorization information associated with the client enrollment data based on the website configuration information; identifying the authenticated client by determining client identification information associated with the client enrollment data; and providing the website with the client identification information based on the integrated client confirmation. The website is isolated from the client enrollment data, the client input data, and the defining of the integrated client confirmation.