Local Password Storage System with Authentication Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user credentials storage and management systems are vulnerable to theft and fraud, with complex public key encryption systems being inefficient and prone to authorization and authentication issues, allowing hackers to access multiple accounts with a single password.

Innovation Solution

A secure user credentials storage and management system that uses a login-key for authentication, allowing access to a secure depository of usernames and passwords within a local or remote network, utilizing various authentication methods including biometrics and dynamic passcodes, and enabling secure storage and retrieval of login details for multiple accounts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If public key encryption is used for securing communications, then security is improved, but system complexity increases and operation speed decreases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the encryption approach from public key encryption to symmetric encryption using AES algorithms. This parameter change in the encryption type reduces system complexity while maintaining security through proper key management via the authentication server.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an authentication server as an intermediary that manages key distribution and authentication. This mediator handles the complex security operations centrally, allowing client devices to use simpler symmetric encryption while still benefiting from robust security through the server's key management capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If public key encryption is used for securing communications, then security is improved, but operation speed decreases

Engineering Contradiction:
ImprovesecurityVSAvoidoperation speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent changes the encryption algorithm from public key encryption to symmetric AES encryption, which is computationally faster. The security requirement is maintained through the authentication server's key management system, allowing quick encryption/decryption operations while preserving security.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The authentication server performs key generation and distribution in advance through the registration process. This preliminary action establishes secure communication channels before actual data transmission, enabling fast symmetric encryption operations during normal operations without compromising security.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If users store passwords in encrypted form on their devices, then accessibility is improved, but security against theft decreases

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity against theft
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication server acts as a mediator that holds the master keys and authentication credentials. While encrypted password files are stored locally on user devices for quick access, the authentication server maintains the ultimate security control through key management, creating a layered security architecture that balances accessibility and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security system into client-side encrypted storage and server-side key management. This segmentation allows local devices to store encrypted credentials for fast access while the authentication server maintains security through centralized key control, preventing unauthorized access even if local storage is compromised.

Inventive Principle:
Principle #1Segmentation

4Ease of operation

If a single master password is used to access all accounts, then ease of access is improved, but vulnerability to single-point compromise increases

Engineering Contradiction:
Improveease of accessVSAvoidvulnerability to compromise
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication system so that the authentication server holds the master authentication credentials while client devices store encrypted password files. This segmentation means that compromising a single client device does not expose all credentials, as the server's key management provides an additional security layer that protects the master password from single-point compromise.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10491588B2Local and remote access apparatus and system for password storage and management
Publication Date: 2019.11.26 KRISHAN BALDEV
  • US10491588B2 patent drawing
  • US10491588B2 patent drawing
  • US10491588B2 patent drawing

AI summary

The present invention is a user credentials' storage and management system installed on the local network consisting of a secured depository of usernames and passwords which can be locally/remotely accessed only by the user after authentication. The user account contains all user credentials' which are stored in a device connected to local network. The user credentials' are stored in a device, which can be accessed by the user via WiFi/Ethernet/etc. The server provides the first level of authentication which connects the user post authentication by computing device to the storage device. The user has to run the required web page, after which the application accesses the user credentials' account, extracts the login credentials and automatically fills or can be manually filled in the appropriate fields. In the case of accessing multiple accounts, then the user credentials; can be copy-pasted from them account and can terminate the session.