Network Identity Authentication via User and Server Agents

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network identity authentication mechanisms based on usernames and passwords lead to password fatigue and credential stuffing attacks due to the need for multiple unique credentials, compromising security and user experience.

Innovation Solution

A network identity authentication method and system that involves a user agent and server agent to acquire and generate unique registration information for target websites, transmitting this information directly to website servers for authentication, thereby eliminating the need for users to remember multiple credentials and reducing the risk of credential stuffing attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users register multiple network identities with different usernames and passwords on multiple websites, then security is improved, but user experience deteriorates due to password fatigue

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an identity management system that acts as an intermediary between users and multiple websites. This system automatically generates, manages, and transmits unique usernames and passwords to websites on behalf of users, eliminating the need for users to manually remember multiple credentials while maintaining security through automated credential distribution

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The identity management system enables self-service by automatically generating unique credentials for each website and handling the authentication process without user intervention. The system autonomously manages the complexity of multiple identities while users simply need to activate the system with a single master password or biometric authentication

Inventive Principle:
Principle #25Self-service

2Ease of operation

If users use identical or similar usernames with a same password for convenience, then ease of operation is improved, but security deteriorates due to credential stuffing attacks

Engineering Contradiction:
ImproveconvenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by generating unique credentials specifically tailored for each website rather than using a universal password. Each website receives customized authentication credentials that are distinct from others, ensuring that a breach at one website does not compromise other accounts while maintaining user convenience through automated management

Inventive Principle:
Principle #3Local quality

3Reliability

If users remember a large number of usernames and passwords, then security is improved through unique credentials, but cognitive load increases resulting in confusion and poor user experience

Engineering Contradiction:
ImprovesecurityVSAvoidcognitive load
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the burden of remembering multiple credentials from the user's cognitive load and transfers it to an automated identity management system. The system takes out the complex task of generating, storing, and recalling multiple unique passwords, leaving users with only a simple master password or biometric authentication to remember

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11310232B2Network identity authentication method and system, and user agent device used thereby
Publication Date: 2022.04.19 GUANGDONG UNIV OF TECH
  • US11310232B2 patent drawing
  • US11310232B2 patent drawing
  • US11310232B2 patent drawing

AI summary

There are provided a network identity authentication method, a network identity authentication system, a user agent device used in the network identity authentication method and the network identity authentication system, and a computer-readable storage medium. The network identity authentication method includes: acquiring, by a user agent, identity information and a registration rule of a target website via a network terminal; acquiring registration information for the target website based on the identity information or generating registration information for the target website according to the registration rule; transmitting the identity information and the registration information to a server agent and sending, by the server agent based on the identity information and the registration information, an authentication request to a website server to complete an authentication process.