Short-Code Authentication for Secure Peer-to-Peer Data Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for secure data exchange between devices, particularly in environments like telemedicine, face challenges in ensuring secure authentication without relying on personal information or compromising user privacy, especially in compliance with regulations like HIPAA.
Innovation Solution
A method involving a system that generates a ledger of authorized participants for a communication session, encoding participant keys and meeting identifiers into short-codes, and redeeming these short-codes for access tokens that enable peer-to-peer connections without storing personal health information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If account registration and login systems are used for authentication, then user authorization can be ensured, but authentication information may be compromised and used by unauthorized devices
Solution Approach 1:
The system generates and distributes short-codes to participants before the communication session begins. These short-codes are redeemable within a specific time window, establishing authentication credentials in advance without requiring users to store or remember complex passwords, thereby preventing authentication information compromise while ensuring reliable authorization
Solution Approach 2:
The patent uses single-use short-codes that are valid only for a specific time window and can be redeemed once to generate an access token. After redemption, the short-code becomes invalid, preventing unauthorized reuse or compromise, thus replacing long-lived authentication credentials with disposable, time-limited ones
2Ease of operation
If personal information is stored for authentication purposes, then user identity can be verified, but compliance with regulations like HIPAA becomes difficult
Solution Approach 1:
The system extracts personal information from the authentication process entirely. Instead of storing or processing user identities, the patent uses anonymous short-codes that are distributed to authorized participants. The short-codes contain no personally identifiable information, yet still enable reliable identity verification within the communication session, thus achieving both ease of operation and HIPAA compliance
Solution Approach 2:
The short-code acts as an intermediary between user identity and system authentication. Rather than directly storing or verifying personal information, the system uses these intermediate codes as proxies for identity verification. The short-codes are distributed securely to authorized users and can be redeemed without exposing any personal health information, bridging the gap between authentication needs and privacy compliance
Data Source
AI summary
Systems and methods authenticating devices for secure data exchange are provided. A ledger of participants authorized to be admitted to a communication session during a time window is generated in response to a scheduling request. For each participant, the ledger includes a participant identifier, a participant key, and a common meeting identifier corresponding to the communication session. The participant key and meeting identifier are encoded into a short-code which is redeemed, by the participants, for an access token authorizing a peer-to-peer connection between devices within a meeting room during the communication session. The participants include a host who may have privileges during the communication session, and one or more clients.


