Local Password Storage System with Authentication Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user credentials storage and management systems are vulnerable to theft and fraud, with complex public key encryption systems being inefficient and prone to authorization and authentication issues, allowing hackers to access multiple accounts with a single password.
Innovation Solution
A secure user credentials storage and management system that uses a login-key for authentication, allowing access to a secure depository of usernames and passwords within a local or remote network, utilizing various authentication methods including biometrics and dynamic passcodes, and enabling secure storage and retrieval of login details for multiple accounts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If public key encryption is used for securing communications, then security is improved, but system complexity increases and operation speed decreases
Solution Approach 1:
The patent changes the encryption approach from public key encryption to symmetric encryption using AES algorithms. This parameter change in the encryption type reduces system complexity while maintaining security through proper key management via the authentication server.
Solution Approach 2:
The patent introduces an authentication server as an intermediary that manages key distribution and authentication. This mediator handles the complex security operations centrally, allowing client devices to use simpler symmetric encryption while still benefiting from robust security through the server's key management capabilities.
2Reliability
If public key encryption is used for securing communications, then security is improved, but operation speed decreases
Solution Approach 1:
The patent changes the encryption algorithm from public key encryption to symmetric AES encryption, which is computationally faster. The security requirement is maintained through the authentication server's key management system, allowing quick encryption/decryption operations while preserving security.
Solution Approach 2:
The authentication server performs key generation and distribution in advance through the registration process. This preliminary action establishes secure communication channels before actual data transmission, enabling fast symmetric encryption operations during normal operations without compromising security.
3Ease of operation
If users store passwords in encrypted form on their devices, then accessibility is improved, but security against theft decreases
Solution Approach 1:
The authentication server acts as a mediator that holds the master keys and authentication credentials. While encrypted password files are stored locally on user devices for quick access, the authentication server maintains the ultimate security control through key management, creating a layered security architecture that balances accessibility and security.
Solution Approach 2:
The patent segments the security system into client-side encrypted storage and server-side key management. This segmentation allows local devices to store encrypted credentials for fast access while the authentication server maintains security through centralized key control, preventing unauthorized access even if local storage is compromised.
4Ease of operation
If a single master password is used to access all accounts, then ease of access is improved, but vulnerability to single-point compromise increases
Solution Approach 1:
The patent segments the authentication system so that the authentication server holds the master authentication credentials while client devices store encrypted password files. This segmentation means that compromising a single client device does not expose all credentials, as the server's key management provides an additional security layer that protects the master password from single-point compromise.
Data Source
AI summary
The present invention is a user credentials' storage and management system installed on the local network consisting of a secured depository of usernames and passwords which can be locally/remotely accessed only by the user after authentication. The user account contains all user credentials' which are stored in a device connected to local network. The user credentials' are stored in a device, which can be accessed by the user via WiFi/Ethernet/etc. The server provides the first level of authentication which connects the user post authentication by computing device to the storage device. The user has to run the required web page, after which the application accesses the user credentials' account, extracts the login credentials and automatically fills or can be manually filled in the appropriate fields. In the case of accessing multiple accounts, then the user credentials; can be copy-pasted from them account and can terminate the session.


