Secure Authentication Information Distribution via Intermediary Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing two-factor authentication systems for remote computer network access face challenges with hardware code generators being prone to loss or damage, requiring manual intervention for seed distribution, and encryption key distribution issues.

Innovation Solution

A system and method for securely distributing authentication information, including receiving a request for authentication information from a remote device, authenticating the user, and returning the authentication information if authenticated, with the option to retrieve and return a seed for access code generation if the access code matches, using secure communication protocols and protected storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware code generators are used for two-factor authentication, then authentication security is improved, but the risk of loss or damage increases and manual administrator intervention is required for seed distribution

Engineering Contradiction:
Improveauthentication securityVSAvoidseed distribution convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces hardware code generators with a software-based authentication system. Instead of relying on physical devices that can be lost or damaged, the system uses software modules that can be distributed and executed on standard computing devices. This substitution eliminates the mechanical/physical component while maintaining authentication security through cryptographic methods and secure key management protocols.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an automated key distribution server as an intermediary between the authentication system and users. This server automatically distributes authentication seeds and keys to authorized users without requiring manual administrator intervention. The intermediary handles secure transmission, storage, and management of authentication credentials, resolving the contradiction between security and operational convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If email is used for seed distribution, then automated distribution is achieved, but security concerns arise due to storage in email systems and backups

Engineering Contradiction:
Improveseed distribution automationVSAvoidseed security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a dedicated key distribution server as an intermediary that handles seed distribution through secure protocols. Instead of using general-purpose email systems, the intermediary provides specialized secure communication channels that do not store seeds in vulnerable locations. The server manages the entire distribution process including encryption, transmission, and confirmation, maintaining both automation and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses cryptographic copying methods where the seed is transmitted in encrypted form and only decrypted at the destination. The system creates secure copies of authentication credentials through cryptographic protocols that ensure the seed exists in secure state throughout the distribution process, eliminating the security vulnerabilities of plain text email storage and backups.

Inventive Principle:
Principle #26Copying

3Reliability

If encryption is applied to seed messages, then security is improved, but encryption key distribution problems arise

Engineering Contradiction:
Improvemessage securityVSAvoidkey distribution complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the key distribution function with the authentication seed distribution process. The key distribution server handles both the encryption keys and the authentication seeds in an integrated manner. By combining these functions, the system eliminates the separate key distribution problem, as the same secure channel used for seed distribution also manages encryption keys, reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements self-service key management where the key distribution server automatically generates, manages, and distributes encryption keys without requiring external key management infrastructure. The system uses public-key cryptography where users generate their own key pairs, and the server automatically handles the distribution of public keys and management of private keys, eliminating the need for complex external key distribution mechanisms.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If software-based code generators are used, then the problem of lost hardware tokens is alleviated, but secure seed distribution mechanisms are still required

Engineering Contradiction:
Improvedevice portabilityVSAvoidseed distribution mechanism
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces an automated key distribution server as an intermediary that handles all seed distribution operations. This intermediary provides a centralized secure mechanism that simplifies the overall system architecture. Instead of requiring complex distributed seed management across multiple devices, the intermediary server manages all authentication credentials centrally, reducing the complexity of seed distribution mechanisms while maintaining software-based portability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal key distribution server that serves multiple functions: distributing authentication seeds, managing encryption keys, verifying user credentials, and handling device registration. This multi-functional intermediary eliminates the need for separate mechanisms for each function, reducing overall system complexity while enabling software-based code generators to be distributed and managed across multiple devices portably.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7809953B2System and method of secure authentication information distribution
Publication Date: 2010.10.05 MALIKIE INNOVATIONS LTD
  • US7809953B2 patent drawing
  • US7809953B2 patent drawing
  • US7809953B2 patent drawing

AI summary

A system and method of distributing authentication information for remotely accessing a computer resource. A request for authentication information, including identity information, is received from a user of a remote device. When the user is authenticated based on the identity information, requested authentication information is retrieved and returned to the remote device. The authentication information, or information generated from the authentication information, is then used for remotely accessing the computer resource.