Secure Logon via Server-Based Soft Token Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing online banking systems face security concerns due to the storage of logon credentials on electronic devices, making users vulnerable to hacking and unauthorized access.
Innovation Solution
Implementing a secure logon process that allows users to enable or disable an expedited logon option, using a particular authentication item like a PIN, and integrating a one-time use soft token for verification, reducing the need for storing credentials locally.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If logon credentials are stored locally on the electronic device to simplify the logon procedure, then ease of operation is improved, but security is worsened due to exposure to hacking and unauthorized access
Solution Approach 1:
The patent extracts the authentication verification process from local device storage and relocates it to a remote server. Instead of storing credentials locally on the electronic device, the system uses a server-based authentication mechanism where credentials are verified remotely, eliminating the security risk of local credential storage while maintaining convenient logon access.
Solution Approach 2:
The patent introduces a server as an intermediary between the electronic device and the authentication process. The server acts as a mediator that receives authentication requests, verifies credentials, and returns authorization status, thereby removing the need for local credential storage and reducing security vulnerabilities associated with device-based authentication.
2Reliability
If traditional authentication procedures are used to enhance security, then reliability is improved, but ease of operation is worsened due to complex logon requirements
Solution Approach 1:
The patent extracts the complex authentication verification burden from the user's electronic device and relocates it to a remote server. By moving the credential verification process to server-based authentication, the system maintains strong security measures while simplifying the user's logon experience, as users only need to provide credentials without managing complex local authentication mechanisms.
Solution Approach 2:
The patent introduces a server as an intermediary that handles complex authentication procedures. The server manages credential verification, token generation, and security protocols, allowing users to benefit from enhanced security without directly interacting with complex authentication mechanisms, thus improving ease of operation while maintaining reliability.
Data Source
AI summary
The present disclosure provides methods and systems for secure logon. One or more method includes: determining, via authentication information provided by a user of an electronic device, that the user is authorized to access an online account provided by the online account provider; providing the user with a selectable option to enable an expedited logon process by which the user can access the online account by solely providing a particular authentication item of the user; receiving a verification credential in response to a next logon attempt using the expedited logon process; and verifying that the received verification credential matches an assigned verification credential provided to the user for use in conjunction with the next logon attempt using the expedited logon process.


