Single-Use Token Authentication via Near Field Communications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face security risks when using the same password across multiple websites, as a single breach can compromise all accounts, and storing passwords in a single location increases financial liability due to loss or theft.
Innovation Solution
A method using a single-use token generated by an authoritative server, conveyed via near field communications technologies, for secure transactions, eliminating the need for password storage and authentication on websites, ensuring only human users can access secured websites.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a user utilizes a single password for multiple websites, then the user's need to memorize passwords is reduced, but a single security breach compromises password-protected account information at each website
Solution Approach 1:
The system segments the authentication process into two independent parts: a persistent credential stored securely in the credential store, and a transient single-use token generated for each transaction. This segmentation allows the user to have one master credential while each transaction uses a unique token, preventing breach propagation across multiple sites.
Solution Approach 2:
The patent employs disposable single-use tokens that are generated for each transaction and then discarded. These short-lived tokens replace traditional reusable passwords, ensuring that even if one token is compromised, it cannot be reused for future transactions, thus maintaining security while simplifying user authentication.
2Ease of operation
If a user stores passwords in a single location, then the user's need to remember passwords is reduced, but loss or compromise of the storage location exposes the user to significant financial liability
Solution Approach 1:
The system introduces a secure credential store as an intermediary between the user and multiple websites. This credential store holds the master credential securely and generates single-use tokens for transactions, acting as a protected mediator that eliminates the need for users to directly store or manage multiple passwords while preventing financial loss through its secure architecture.
Solution Approach 2:
The system implements prior cushioning by using single-use tokens that are pre-generated and validated before transactions occur. Each token is designed to be used only once and then invalidated, providing a safety mechanism that cushions against potential theft or loss of the credential store, as compromised tokens cannot be reused.
3Ease of operation
If traditional password authentication is used, then users can access websites, but users are vulnerable to unauthorized access and password theft
Solution Approach 1:
The system transitions from static password authentication to dynamic single-use token authentication. Each token is generated fresh for each transaction and is valid only for that specific transaction, making the authentication mechanism dynamic and adaptive. This eliminates the vulnerability of static passwords while maintaining ease of access through automated token generation and validation.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enhances transaction security by preventing unauthorized access, reducing the risk of password breaches, and eliminating the need for users to remember multiple passwords, while protecting sensitive information from theft.
Implementation Method 1
transmit a signal by way of a near field communications transmitter coupled to the one or more processors, wherein the signal represents a single use token
Implementation Method 2
a logic module for use with a browser may comprise a control element for activating a near field communications receiver for transmitting and/or receiving an acoustic signal, time-varying magnetic field, optical communication signal
Data Source
AI summary
The present invention is generally related to client and computing platforms that may be used for conducting secure transactions.

