Passwordless Security Device Authentication Via Trusted Device Proximity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing number of usernames and passwords required for various systems complicates user authentication, leading to issues such as password updates and the need to carry electronic storage, which can be lost, and poses security risks.
Innovation Solution
A security device authenticates users by inserting an object, such as a card, which identifies a user profile and selects a trusted device to receive an access code, eliminating the need for passwords and enhancing security through proximity verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If users authenticate using multiple usernames and passwords for different systems, then access to various systems is enabled, but the complexity of remembering and managing credentials increases
Solution Approach 1:
The patent implements a universal authentication system where a single security device can authenticate users across multiple different systems. Instead of requiring separate credentials for each system, the security device serves as a universal authentication mechanism that works with various systems, thereby reducing credential management complexity while maintaining access versatility.
Solution Approach 2:
The security device acts as an intermediary between the user and multiple systems. Rather than the user directly managing credentials for each system, the security device mediates the authentication process by storing and managing credentials centrally, then presenting appropriate credentials to different systems as needed.
2Ease of operation
If users store usernames and passwords in electronic storage, then retrieval of credentials becomes easier, but the risk of loss and security breaches increases
Solution Approach 1:
The patent segments the authentication process into multiple independent components: the security device stores credentials securely, the system receives authentication requests, and the security device responds with appropriate credentials. This segmentation isolates the sensitive credential storage from potential attack vectors, maintaining ease of retrieval while improving security.
Solution Approach 2:
The security device provides self-service authentication by automatically managing credential storage, retrieval, and presentation without requiring users to manually handle credentials. The device autonomously protects credentials from loss and breaches while enabling easy access when needed.
3Reliability
If users must update electronic storage every time a password changes, then current credentials are maintained, but the time and effort required for updates increases
Solution Approach 1:
The system implements feedback mechanisms where the security device automatically detects when credentials need updating and retrieves updated credentials from the system without requiring manual user intervention. The device receives feedback from the system about credential status and autonomously updates its stored credentials, maintaining currency while eliminating update time for users.
4Adaptability or versatility
If users carry electronic storage everywhere passwords may be needed, then access to multiple systems is maintained, but the risk of losing all credentials increases
Solution Approach 1:
The security device serves as a reliable intermediary that users carry instead of multiple credentials. It maintains communication with the authentication system to retrieve updated credentials as needed, ensuring both adaptability for accessing multiple systems and reliability for credential availability even when the device is lost or damaged.
Data Source
AI summary
Methods and systems are disclosed herein for authenticating a user. A security device may use an object associated with a user and a device of the user to authenticate the user, for example, if the user has forgotten a password. A user may insert the object (e.g., a card, or other object) into the security device and may select an option to authenticate via a device that is trusted by both the security device and the user, rather than authenticating by entering a password at the security device.


