Optical Code Authentication via Host Server Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional password-based authentication methods are vulnerable to interception techniques and become less secure due to the decreasing length of passwords on smaller devices, making them prone to forgetting and compromising security.
Innovation Solution
A method involving a unique code generated by a host server, which is optically presented to the user and verified through a second device, eliminating the need for manual data entry and enhancing security by using device-identifying information to retrieve session and user-identifying information, thus preventing interception methods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If passwords are used for authentication, then user identification is achieved, but security is compromised due to interception techniques and reduced password length on smaller devices
Solution Approach 1:
The patent extracts the authentication data from the user's direct input and stores it on the service provider's server. The user only needs to provide a simple device identifier, while the actual authentication credentials remain secured on the server, eliminating exposure to interception attacks.
Solution Approach 2:
The patent introduces a server as an intermediary between the user and the authentication process. The server acts as a trusted third party that holds the authentication credentials and verifies the user's device identifier, removing the need for users to handle sensitive password data directly.
2Productivity
If manual password entry is required, then authentication can be performed, but the process becomes time-consuming and error-prone
Solution Approach 1:
The patent implements self-service authentication where the system automatically retrieves and verifies authentication credentials without requiring manual user input. The user's device identifier is automatically processed by the server, which handles the entire authentication sequence without user intervention.
Solution Approach 2:
The patent replaces the mechanical process of manual keyboard entry with automated electronic identification. Instead of physically typing passwords, the system uses automatic device identifier recognition and electronic verification, eliminating the time and errors associated with manual input.
3Volume of moving object
If device size is reduced, then portability is improved, but input capability deteriorates leading to shorter passwords and reduced security
Solution Approach 1:
The patent extracts the complex input requirement from the user interface and relocates it to the server. Small devices only need to present their device identifier, while the server handles the complex authentication logic and credential verification, eliminating the need for large keyboards or complex input mechanisms.
Solution Approach 2:
The patent introduces a server intermediary that bridges the gap between limited small-device input capabilities and secure authentication requirements. The server translates simple device identifier input into full authentication credentials, allowing small devices to maintain security without requiring extensive input interfaces.
Data Source
AI summary
A method, of authenticating a user with a service and a server having means to enable a user to be authenticated with a service. The method having the steps of, the user requesting a session with the service on a first device. The server requesting a unique code from a host server, the host server generating the unique code, associating it with a session-identifier. The session-identifier containing information relating to the code request. The host server then sending the unique code, which does not contain the session-identifier, to the service. The server then optically presents the unique code to the user on a display of the first device. The code is then acquired by a verification application running on a second device. Optionally the first device and the second device may be the same device. The second device is previously registered with the host server. The verification application sends the unique code, and device-identifying information of the second device, to the host server. The host server, on receiving the unique code and device-identifying information, uses the unique code to retrieve the session-identifier, and uses the device-identifying information to retrieve associated user-identifying information. This user-identifying information is stored on the host server. The host server then sends the user-identifying information to the service.


