Mobile Authentication System Decentralizing Credential Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for user authentication, such as auto-populating login credentials in web browsers, suffer from security vulnerabilities due to storage on accessible devices, require users to remember multiple credentials, and encourage the use of simple passwords for memory assistance, leading to potential breaches and forgotten credentials.

Innovation Solution

A system and method utilizing a mobile communication device connected to a wireless network, an authentication server, and a computing device for secure authentication, where the authentication server processes user requests, generates decryption security information, and forwards it to the mobile device, which processes and encrypts credentials, allowing secure access to online resources without storing sensitive information on the computing device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If web browser auto-populates authentication fields, then user convenience is improved, but security is worsened due to storage on accessible devices

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the authentication credentials from the web browser environment and stores them on a remote authentication server. The browser only receives auto-populated fields without storing sensitive credentials locally, thereby maintaining user convenience while eliminating the security risk of local storage on accessible devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an authentication server as an intermediary between the user and multiple online resources. The server stores credentials securely and provides them temporarily for authentication, acting as a mediator that enables convenient access without requiring local storage on client devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If user stores multiple credential sets, then access to multiple resources is enabled, but memory burden and security risk increase

Engineering Contradiction:
Improveaccess to multiple resourcesVSAvoidcredential management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication server provides a universal credential storage service that supports access to multiple online resources through a single interface. Users interact with one authentication system that handles multiple resources, eliminating the need to manage separate credential sets for each resource while maintaining versatile access capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges multiple credential sets into a single centralized storage location on the authentication server. Instead of maintaining separate credentials for each online resource on local devices, all credentials are combined and managed in one secure location, simplifying credential management while enabling access to multiple resources.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If user uses simple credentials for memory assistance, then ease of recall is improved, but security is worsened

Engineering Contradiction:
Improvecredential recallVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent creates a copy of the credential management function on the remote authentication server. Instead of requiring users to remember complex credentials, the system copies the credentials to a secure remote location where they can be retrieved automatically, allowing users to use simpler recall methods while maintaining strong credentials for security.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8689297B2System, devices and method for secure authentication
Publication Date: 2014.04.01 MALIKIE INNOVATIONS LTD
  • US8689297B2 patent drawing
  • US8689297B2 patent drawing
  • US8689297B2 patent drawing

AI summary

A system, devices and method for authenticating a user requesting access, through a computing device connected to a network, to an on-line resource hosted by a server in communication with the network. The system, devices and method employing an authentication server and a mobile communications device in communication over a wireless network. The authentication server forwarding an authentication to the mobile communications device. Optionally, the authentication server also returning security information related to the authentication in response to the request. The mobile communications device operative to receive and process the authentication, and forward the processed authentication to the computing device over a short-range communications link.