Server-Mediated Authentication Without Client Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network-based systems lack effective protection against unauthorized access to personal data and assets, particularly when using untrusted client devices or systems that may be compromised by malware or viruses, such as those found in internet cafés.
Innovation Solution
A security mechanism utilizing a mobile wireless communications device to authenticate users to a server without providing authentication tokens to the client device, employing encoded images and secure communication protocols like TLS to ensure secure sign-in, transaction confirmation, and logoff processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If authentication tokens are provided to client devices for network access, then ease of operation is improved, but security against unauthorized access deteriorates
Solution Approach 1:
The patent introduces a server as an intermediary between the client device and the authentication token. The server generates and holds the authentication tokens, receiving requests from client devices without storing tokens locally on them. This intermediary approach allows convenient authentication for users while preventing malware or viruses on client devices from compromising security by never having direct access to the tokens.
2Ease of operation
If client devices are made accessible for public use, then ease of operation is improved, but reliability of secure access deteriorates
Solution Approach 1:
The patent extracts the authentication token storage and management functionality from the client device and relocates it to a secure server environment. This extraction allows client devices to be publicly accessible and easily operable while the critical security function of token management remains isolated in a controlled server environment, ensuring reliability of secure access regardless of the client device's trustworthiness.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Apparatus, systems, and methods provide a mechanism to enhance the security of operating client devices with systems controlling secure data. Various embodinents includes apparatus and methods to authenticate a communication session between a server and a client device without providing authentication tokens to the client device. Additional apparatus, systems, and methods are disclosed.