Thin Client Authentication via Mobile Biometric Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Thin clients lack biometric authentication capabilities due to cost constraints, making password-based authentication vulnerable to hacking and difficult to manage, especially in corporate environments where strict security requirements are enforced.

Innovation Solution

Utilizing independent mobile devices with biometric scanners to perform authentication on thin clients by creating mappings between mobile device information and domain identities, allowing users to authenticate using biometric data and log into their thin client desktops without typing passwords.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric scanners are added to thin clients, then authentication security is improved, but device cost increases

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent uses a mobile device as an intermediary to perform biometric authentication. Instead of adding biometric scanners to thin clients, the system leverages the mobile device's existing biometric capabilities (fingerprint sensor, facial recognition) to authenticate the user, then uses this authentication to log into the thin client session. This mediator approach transfers the authentication function from the thin client to the mobile device, resolving the cost-security contradiction.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system leverages the mobile device's own built-in biometric authentication capabilities to perform the authentication. The mobile device uses its native fingerprint sensor or facial recognition system to verify the user's identity, eliminating the need for external biometric hardware on the thin client. This self-service approach allows the mobile device to provide the biometric authentication function it already possesses, avoiding additional costs.

Inventive Principle:
Principle #25Self-service

2Ease of manufacture

If password-based authentication is used, then device cost is reduced, but security is worsened

Engineering Contradiction:
Improvedevice costVSAvoidauthentication security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The mobile device acts as an intermediary that bridges the gap between low-cost thin clients and secure authentication. The thin client maintains simple password-based or token-based authentication, while the mobile device provides the biometric security layer. The authentication service on the server coordinates between the thin client's authentication mechanism and the mobile device's biometric verification, achieving both cost-effectiveness and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If complex password requirements are enforced, then security is improved, but ease of operation is worsened

Engineering Contradiction:
Improveauthentication securityVSAvoidpassword management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical act of typing complex passwords with a biometric scanning process. Instead of requiring users to manually enter lengthy, complex passwords with special characters and numbers, the system uses the mobile device's biometric scanner to automatically verify the user's identity. This substitution eliminates the need for users to remember and type complex passwords, significantly improving ease of operation while maintaining or enhancing security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10523665B2Authentication on thin clients using independent devices
Publication Date: 2019.12.31 DELL MARKETING CORP
  • US10523665B2 patent drawing
  • US10523665B2 patent drawing
  • US10523665B2 patent drawing

AI summary

Authentication can be performed on thin clients using independent mobile devices. Because many users have smart phones or other similar mobile devices that include biometric scanners, such mobile devices can be leveraged to perform authentication of users as part of logging in to a thin client desktop. A mapping can be created on a central server between a user's mobile device and the user's domain identity. A mapping can also be created between the user's domain identity and the user's thin client desktop. Then, when a user desires to log in to his thin client desktop, the user can employ the appropriate biometric scanner on his mobile device to perform authentication. The central server can then rely on this authentication to identify and log the user into his thin client desktop.