Network Authentication via Hardware Identification Codes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network authentication methods are costly and inconvenient due to the need for multiple identity verification devices for different websites, and are vulnerable to hacking attempts that intercept user IDs, passwords, and transaction data.

Innovation Solution

A network authentication method using a network server and user end device that stores a terminal program with unique hardware components, allowing for secure authentication through exclusive communication channels and automatic verification of hardware identification codes without user operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware identity verification devices (tokens, cards) are used for each user, then authentication security is improved, but device cost and customer service cost increase significantly

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses the user's existing terminal device (computer, smartphone) which already possesses hardware components (CPU, memory, storage, communication module) for multiple purposes including authentication. The terminal device serves both as a general computing device and as an authentication device, eliminating the need for separate dedicated authentication hardware for each user.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The terminal device automatically collects its own hardware information (CPU ID, memory ID, storage ID, communication module ID) and uses this self-collected information for authentication. The device serves itself by providing the authentication data without requiring external authentication hardware or manual intervention.

Inventive Principle:
Principle #25Self-service

2Reliability

If separate identity verification devices are required for different web sites, then authentication security is improved, but user convenience deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The user's terminal device serves as a universal authentication device for multiple different websites and services. Instead of requiring separate tokens or cards for each website, the same terminal device with its inherent hardware information can authenticate the user across different platforms, greatly improving convenience.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the authentication function with the terminal device itself. The hardware information of the terminal is combined with user credentials to create a unified authentication mechanism that works across multiple websites, eliminating the need to manage multiple separate authentication devices.

Inventive Principle:
Principle #5Merging (Combining)

3Device complexity

If traditional single communication channel is used between user and server, then system simplicity is maintained, but security against interception and manipulation attacks deteriorates

Engineering Contradiction:
Improvesystem simplicityVSAvoidsecurity vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the communication path into two separate channels: a first communication channel for general web browsing and a second communication channel specifically for authentication data transmission. This segmentation allows the authentication channel to be protected with higher security measures while keeping the general browsing channel simple.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an authentication server as an intermediary between the user's terminal and the target website server. The authentication server receives authentication requests through the secure second communication channel, verifies the terminal's hardware information, and then facilitates the actual authentication with the target server, adding a security layer without complicating the overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9667626B2Network authentication method and device for implementing the same
Publication Date: 2017.05.30 LYDSEC DIGITAL TECH CO LTD
  • US9667626B2 patent drawing
  • US9667626B2 patent drawing
  • US9667626B2 patent drawing

AI summary

A method is to be implemented using a network authentication device and a user end for authenticating the user end. The network authentication device stores hardware information associated with unique identification codes of hardware components of the user end. In the method, the user end executes a terminal program for scanning the hardware components to obtain the identification codes, for establishing a hardware list according to the identification codes, and for automatically sending to the network authentication device verification data associated with the hardware list without user operation. The network authentication device verifies identity of the user end based on the verification data and the hardware information.