Short-Code Authentication for Secure Peer-to-Peer Data Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for secure data exchange between devices, particularly in environments like telemedicine, face challenges in ensuring secure authentication without relying on personal information or compromising user privacy, especially in compliance with regulations like HIPAA.

Innovation Solution

A method involving a system that generates a ledger of authorized participants for a communication session, encoding participant keys and meeting identifiers into short-codes, and redeeming these short-codes for access tokens that enable peer-to-peer connections without storing personal health information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If account registration and login systems are used for authentication, then user authorization can be ensured, but authentication information may be compromised and used by unauthorized devices

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication information compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system generates and distributes short-codes to participants before the communication session begins. These short-codes are redeemable within a specific time window, establishing authentication credentials in advance without requiring users to store or remember complex passwords, thereby preventing authentication information compromise while ensuring reliable authorization

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses single-use short-codes that are valid only for a specific time window and can be redeemed once to generate an access token. After redemption, the short-code becomes invalid, preventing unauthorized reuse or compromise, thus replacing long-lived authentication credentials with disposable, time-limited ones

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Ease of operation

If personal information is stored for authentication purposes, then user identity can be verified, but compliance with regulations like HIPAA becomes difficult

Engineering Contradiction:
Improveuser identity verificationVSAvoidregulatory compliance
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system extracts personal information from the authentication process entirely. Instead of storing or processing user identities, the patent uses anonymous short-codes that are distributed to authorized participants. The short-codes contain no personally identifiable information, yet still enable reliable identity verification within the communication session, thus achieving both ease of operation and HIPAA compliance

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The short-code acts as an intermediary between user identity and system authentication. Rather than directly storing or verifying personal information, the system uses these intermediate codes as proxies for identity verification. The short-codes are distributed securely to authorized users and can be redeemed without exposing any personal health information, bridging the gap between authentication needs and privacy compliance

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12284284B2System and method of authenticating devices for secure data exchange
Publication Date: 2025.04.22 HUMANA INC
  • US12284284B2 patent drawing
  • US12284284B2 patent drawing
  • US12284284B2 patent drawing

AI summary

Systems and methods authenticating devices for secure data exchange are provided. A ledger of participants authorized to be admitted to a communication session during a time window is generated in response to a scheduling request. For each participant, the ledger includes a participant identifier, a participant key, and a common meeting identifier corresponding to the communication session. The participant key and meeting identifier are encoded into a short-code which is redeemed, by the participants, for an access token authorizing a peer-to-peer connection between devices within a meeting room during the communication session. The participants include a host who may have privileges during the communication session, and one or more clients.