Single-Use Connection Code Authentication via Trusted Entity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face complexity and security issues when managing multiple passwords for different services, often resorting to insecure practices like writing them down or using password management applications, due to the need to remember unique passwords for each service.
Innovation Solution
A method where a trusted entity generates a single-use connection code for a user device, allowing access to a service by clicking on a Uniform Resource Locator (URL) without requiring password memorization, using a contact address associated with the user identifier, such as a phone number or email, for secure and simplified access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users choose different passwords for each service, then security level is improved, but ease of operation deteriorates due to difficulty in remembering multiple passwords
Solution Approach 1:
The patent introduces a trusted entity as an intermediary between the user and multiple services. This entity manages authentication by generating unique connection codes for each service, eliminating the need for users to remember multiple passwords while maintaining security through centralized credential management.
Solution Approach 2:
The authentication process is segmented into distinct components: a trusted entity that generates connection codes, a contact address for code delivery, and service-specific identifiers. This segmentation allows the system to maintain security through unique credentials for each service while simplifying user interaction to a single authentication step.
2Ease of operation
If users use the same password for multiple services, then ease of operation is improved, but security level deteriorates
Solution Approach 1:
The trusted entity acts as a mediator that generates unique connection codes for each service without requiring users to remember multiple passwords. The entity manages the credential distribution securely, delivering unique codes to the user's contact address for each service authentication.
Solution Approach 2:
The system changes the authentication parameter from static passwords to dynamic, service-specific connection codes. These codes are generated on-demand by the trusted entity and are unique to each service-user combination, providing both ease of operation and enhanced security.
3Ease of operation
If users write down passwords or use password managers, then ease of operation is improved, but object-generated harmful factors increase due to security risks from stored credentials
Solution Approach 1:
The trusted entity serves as a secure intermediary that eliminates the need for users to store passwords locally. Authentication credentials are generated and delivered securely through the contact address mechanism, removing the harmful factor of stored credentials while maintaining ease of operation.
Solution Approach 2:
The system uses disposable connection codes that are valid only for a single authentication attempt. These short-living credentials eliminate the need for permanent password storage, as each code is used once and then discarded, thereby removing security risks associated with stored credentials.
Data Source
Figure 1~5
Figure 2
Figure 3
AI summary
The invention relates to a technique for connecting a user device (10, 11) to a service (30). The device sends a request to connect to the service, a user identifier of the device from a trusted entity (40) being associated with said request. The trusted entity sends a reply to said request back to the device. This reply comprises data about a uniform resource locator associated with said service and a single-use code and is sent to a contact address associated with the user identifier from the trusted entity. The device then sends a request to access a page of the service, the address of which corresponds to said data, the received single-use code being associated with said access request. Connection to the service is authorized for the service identifier associated with the user identifier from the trusted entity, when a single-use code received from a server implementing the service, in combination with a service identifier request, is valid.