Network Authentication Using Hardware Signatures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network authentication methods are costly and inconvenient due to the need for multiple identity verification devices for different websites, and are vulnerable to data tampering and theft, especially with increasing web transactions and sophisticated hacking techniques.
Innovation Solution
A network authentication method using a network authentication device that stores hardware information from user-end components with unique identification codes, allowing the user-end to execute a terminal program to scan and verify these components, and generate digital signatures for secure transactions, thereby eliminating the need for multiple authentication devices and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware identity verification devices (tokens, cards) are used for each user, then authentication security is improved, but device cost and customer service cost increase significantly
Solution Approach 1:
The patent creates a virtual copy of the hardware verification device by generating a digital image of the hard disk signature (a unique hardware identifier). This digital copy is stored on the server and used for authentication purposes, eliminating the need for physical tokens or cards while maintaining security. The hard disk signature acts as a reproducible digital representation of the user's hardware identity.
Solution Approach 2:
The patent replaces the mechanical/physical verification system (tokens, cards, readers) with a software-based authentication mechanism. Instead of requiring physical hardware interaction, the system uses software to capture, store, and verify hard disk signatures, substituting the mechanical verification process with an automated software solution that reduces hardware costs.
2Reliability
If different identity verification devices are required for different web sites, then authentication security is improved, but user convenience deteriorates
Solution Approach 1:
The patent creates a universal authentication mechanism where a single hard disk signature can serve multiple authentication purposes across different websites and services. The hard disk signature is a unique identifier that works universally, eliminating the need for users to manage multiple site-specific verification devices. This single signature can be used for web banking, online shopping, and other authenticated services.
Solution Approach 2:
The patent merges the functionality of multiple verification devices into a single authentication system based on the hard disk signature. Instead of requiring separate tokens or cards for different services, the system combines all authentication needs into one unified mechanism that leverages the user's existing hardware identity, simplifying the user experience while maintaining security.
3Reliability
If hardware equipments are changed frequently to prevent hacking, then data security is improved, but cost for changing hardware increases
Solution Approach 1:
The patent performs preliminary authentication by verifying the hard disk signature before allowing any transactions or data access. This preliminary verification step ensures that even if hardware is compromised later, the initial authentication barrier prevents unauthorized access. The system proactively checks the hardware identity in advance, eliminating the need for frequent hardware changes to maintain security.
Solution Approach 2:
The patent creates a digital copy of the hardware signature that can be verified without physically changing the hardware. This digital replica allows the system to authenticate users based on their existing hardware identity without requiring physical hardware updates or replacements, maintaining security while avoiding the costs associated with frequent hardware changes.
4Ease of operation
If traditional authentication methods (user ID, password) are used, then ease of operation is improved, but vulnerability to theft and manipulation increases
Solution Approach 1:
The patent merges traditional software-based authentication (user ID and password) with hardware-based authentication (hard disk signature) into a unified security system. This combination maintains the ease of entering user credentials while adding a hardware-level security layer that is difficult to steal or manipulate. The hard disk signature serves as an additional authentication factor that works seamlessly with traditional login methods.
Solution Approach 2:
The patent creates a composite authentication system that combines multiple authentication mechanisms (knowledge-based: password; possession-based: hard disk signature) into a unified security framework. This composite approach leverages the strengths of both methods: the ease of use of passwords and the security of hardware identifiers, creating a more robust authentication system that resists various attack vectors while remaining user-friendly.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A network authentication method is to be implemented using a network authentication device (1, 8) and a user end (2, 6) for authenticating the user end (2, 6). The network authentication method includes the steps of: configuring the network authentication device (1, 8) to store hardware information (10a-10c, 633) associated with unique identification codes of hardware components of the user end (2, 6); when it is intended to verify identity of the user end (2, 6), configuring the user end (2, 6) to execute a terminal program (221, 631) stored therein for scanning the hardware components thereof to obtain the identification codes of the hardware components, for establishing a hardware list according to the identification codes thus obtained, and for sending to the network authentication device (1, 8) verification data that is associated with the hardware list; and configuring the network authentication device (1, 8) to verify identity of the user end (2, 6) based on relationship between the verification data received from the user end (2, 6) and the hardware information (10a-10c, 633) stored therein.