Mobile Authentication System Decentralizing Credential Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for user authentication, such as auto-populating login credentials in web browsers, suffer from security vulnerabilities due to storage on accessible devices, require users to remember multiple credentials, and encourage the use of simple passwords for memory assistance, leading to potential breaches and forgotten credentials.
Innovation Solution
A system and method utilizing a mobile communication device connected to a wireless network, an authentication server, and a computing device for secure authentication, where the authentication server processes user requests, generates decryption security information, and forwards it to the mobile device, which processes and encrypts credentials, allowing secure access to online resources without storing sensitive information on the computing device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If web browser auto-populates authentication fields, then user convenience is improved, but security is worsened due to storage on accessible devices
Solution Approach 1:
The patent extracts the authentication credentials from the web browser environment and stores them on a remote authentication server. The browser only receives auto-populated fields without storing sensitive credentials locally, thereby maintaining user convenience while eliminating the security risk of local storage on accessible devices.
Solution Approach 2:
The patent introduces an authentication server as an intermediary between the user and multiple online resources. The server stores credentials securely and provides them temporarily for authentication, acting as a mediator that enables convenient access without requiring local storage on client devices.
2Adaptability or versatility
If user stores multiple credential sets, then access to multiple resources is enabled, but memory burden and security risk increase
Solution Approach 1:
The authentication server provides a universal credential storage service that supports access to multiple online resources through a single interface. Users interact with one authentication system that handles multiple resources, eliminating the need to manage separate credential sets for each resource while maintaining versatile access capabilities.
Solution Approach 2:
The patent merges multiple credential sets into a single centralized storage location on the authentication server. Instead of maintaining separate credentials for each online resource on local devices, all credentials are combined and managed in one secure location, simplifying credential management while enabling access to multiple resources.
3Ease of operation
If user uses simple credentials for memory assistance, then ease of recall is improved, but security is worsened
Solution Approach 1:
The patent creates a copy of the credential management function on the remote authentication server. Instead of requiring users to remember complex credentials, the system copies the credentials to a secure remote location where they can be retrieved automatically, allowing users to use simpler recall methods while maintaining strong credentials for security.
Data Source
AI summary
A system, devices and method for authenticating a user requesting access, through a computing device connected to a network, to an on-line resource hosted by a server in communication with the network. The system, devices and method employing an authentication server and a mobile communications device in communication over a wireless network. The authentication server forwarding an authentication to the mobile communications device. Optionally, the authentication server also returning security information related to the authentication in response to the request. The mobile communications device operative to receive and process the authentication, and forward the processed authentication to the computing device over a short-range communications link.


