Server-Mediated Authentication Without Client Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network-based systems lack effective protection against unauthorized access to personal data and assets, particularly when using untrusted client devices or systems that may be compromised by malware or viruses, such as those found in internet cafés.

Innovation Solution

A security mechanism utilizing a mobile wireless communications device to authenticate users to a server without providing authentication tokens to the client device, employing encoded images and secure communication protocols like TLS to ensure secure sign-in, transaction confirmation, and logoff processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If authentication tokens are provided to client devices for network access, then ease of operation is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improveauthentication convenienceVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a server as an intermediary between the client device and the authentication token. The server generates and holds the authentication tokens, receiving requests from client devices without storing tokens locally on them. This intermediary approach allows convenient authentication for users while preventing malware or viruses on client devices from compromising security by never having direct access to the tokens.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If client devices are made accessible for public use, then ease of operation is improved, but reliability of secure access deteriorates

Engineering Contradiction:
Improvesystem accessibilityVSAvoidsecure access guarantee
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the authentication token storage and management functionality from the client device and relocates it to a secure server environment. This extraction allows client devices to be publicly accessible and easily operable while the critical security function of token management remains isolated in a controlled server environment, ensuring reliability of secure access regardless of the client device's trustworthiness.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2602735B1Secure authentication
Publication Date: 2018.04.04 BLACKBERRY LTD
  • EP2602735B1 patent drawingFigure 1
  • EP2602735B1 patent drawingFigure 2
  • EP2602735B1 patent drawingFigure 3

AI summary

Apparatus, systems, and methods provide a mechanism to enhance the security of operating client devices with systems controlling secure data. Various embodinents includes apparatus and methods to authenticate a communication session between a server and a client device without providing authentication tokens to the client device. Additional apparatus, systems, and methods are disclosed.