Passwordless Authentication via Bluetooth Link and Encrypted Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current user authentication systems are not user-friendly, often requiring multiple credentials and are vulnerable to hacking due to users' tendency to reuse or choose simple passwords, which compromises security.
Innovation Solution
A method and system for authenticating a communications terminal using an authentication server connected via a gateway terminal, employing a Bluetooth interface to establish a virtual data transmission link, allowing authentication without the need for a password, by using a predefined data transmission interface and encrypted data for verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication systems requiring login and password are used, then security can be maintained to some extent, but user friendliness deteriorates due to complexity and user vulnerabilities
Solution Approach 1:
The patent extracts the password entry requirement from the authentication process. The system allows authentication to proceed without requiring the user to enter a password, instead using device-based authentication mechanisms where the communication terminal itself serves as the authentication credential, thereby eliminating the weak link of user-managed passwords while maintaining security
Solution Approach 2:
The patent introduces an authentication server as an intermediary between the user and the service provider. This server handles the authentication process using device identifiers and cryptographic verification, mediating the authentication to eliminate the need for users to directly manage passwords while maintaining secure authentication
2Reliability
If users are required to remember multiple passwords for different services, then security can be maintained per service, but ease of operation deteriorates due to user burden
Solution Approach 1:
The patent implements a universal authentication mechanism where the communication terminal device itself serves as the authentication credential across multiple services. The device identifier and cryptographic capabilities of the terminal provide a universal authentication method that works across different services without requiring users to remember multiple passwords, while the authentication server maintains service-specific security requirements
3Ease of operation
If simple or reused passwords are used by users, then ease of operation is maintained, but security deteriorates due to vulnerability to hacking
Solution Approach 1:
The patent extracts the password element entirely from the authentication process. Instead of relying on user-chosen passwords that may be simple or reused, the system uses device-based authentication where the communication terminal's unique identifier and cryptographic capabilities provide security, eliminating the vulnerability of weak passwords while keeping operation simple for users
Solution Approach 2:
The communication terminal itself serves as the authentication credential. The device's unique identifier and cryptographic functions provide the authentication mechanism without requiring user-managed passwords. The terminal autonomously provides authentication credentials to the authentication server, eliminating the need for users to create or remember passwords while maintaining strong security
Data Source
AI summary
A method is provided for authenticating a user's communications terminal with an authentication server connected to a gateway terminal by using a communications network. The method includes: obtaining a piece of data representing an identity of the user from the gateway terminal; configuring, by the authentication server, a data transmission link between the authentication server and the terminal, using a predefined data transmission interface of the gateway terminal and as a function of the piece of data representing the identity of the user; transmitting, by the authentication server, to the terminal, a piece of encrypted data for checking authentication, using the data transmission link; receiving, by the authentication user, coming from the terminal, a piece of encrypted data for counter-checking authentication; issuing an assertion of authentication of the user when the piece of data for the counter-checking of authentication corresponds to the piece of data for checking authentication.

