Separate Authentication Device Token Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current remote login technologies are vulnerable to password theft and require users to manage complex and numerous IDs and passwords, leading to user inconvenience and security risks.
Innovation Solution
A system using a separate device for authentication, where a token is generated and verified through a chain of software agents, ensuring secure access to information by combining traditional credentials with supplemental information like biometrics and environmental data, and using encryption keys that are not stored on user devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional ID and password authentication is used, then users can access remote systems, but the system becomes vulnerable to password theft and compromise
Solution Approach 1:
The patent extracts the authentication credentials from the user device by using a separate authentication device to generate and hold the password temporarily. The password is never stored on the user device, eliminating the vulnerability to password theft from compromised devices. The authentication device acts as a dedicated security appliance that isolates credential management from general-purpose computing devices.
Solution Approach 2:
The patent introduces an intermediary authentication device that mediates between the user and the remote system. This device generates passwords on-demand, transmits them through secure channels, and then securely deletes them. The intermediary architecture prevents direct exposure of credentials on user devices while maintaining authentication functionality.
2Adaptability or versatility
If users maintain multiple IDs and passwords in a secret notebook, then they can access different systems, but the complexity of management increases and security risks grow
Solution Approach 1:
The authentication device provides universal functionality for accessing multiple remote systems. A single device can generate credentials for various systems, eliminating the need for users to manage separate password notebooks for different services. The device adapts to different authentication requirements while maintaining a unified management interface.
Solution Approach 2:
The authentication device automatically manages the complexity of multiple credentials by generating, storing, and rotating passwords without requiring manual user intervention. The system self-manages the credential lifecycle including generation, transmission, and secure deletion, freeing users from the burden of manual password management while maintaining multi-system access capability.
3Reliability
If passwords are changed periodically by administrators, then security is maintained, but user inconvenience and management difficulty increase
Solution Approach 1:
The authentication device implements dynamic password management where credentials can be changed on-demand rather than following fixed periodic schedules. When administrators need to rotate credentials for security reasons, the device can immediately generate new passwords and invalidate old ones without requiring user action or system downtime, making the security maintenance process flexible and efficient.
4Ease of operation
If encryption keys are stored on user devices, then data access is enabled, but the keys become vulnerable to discovery by adversaries
Solution Approach 1:
The patent extracts encryption key storage from user devices and relocates it to dedicated authentication devices or secure enclaves. Keys are generated and stored in isolated security modules rather than on general-purpose devices that are more vulnerable to attacks. This separation ensures that even if user devices are compromised, the encryption keys remain protected in their isolated storage location.
Data Source
AI summary
A system that incorporates the subject disclosure may perform, for example, operations including obtaining a request from a mobile device to allow user access to restricted content of a separate device. The process further includes forwarding a token to the separate device by way of a second wireless network, to obtain a separate device token, and forwarding the token to the first device by way of the first network to obtain a mobile device token, wherein the mobile device token is forwarded to the separate device by way of a third network. A confirmation that the token was obtained at the separate device is based on the result of the comparison indicating a match between the mobile device token and the separate device token. Access to the restricted content of the separate device is authorized based on to the confirmation. Other embodiments are disclosed.


