Third Party Token Authentication for Password Fatigue
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The proliferation of accounts and associated authentication credentials due to the increasing use of information technology and secure transaction technology leads to 'password fatigue,' where users compromise security to manage multiple passwords.
Innovation Solution
A method involving an identity provider computing system that generates a unique user token based on user identification and transmits it to a third party provider for authentication, eliminating the need for traditional password-based authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional password-based authentication is used for multiple accounts, then users can access various services, but security is compromised due to password fatigue and reuse
Solution Approach 1:
The patent introduces an intermediary authentication system that uses third-party providers and tokens as mediators between users and services. Instead of users managing multiple passwords directly, the system uses an intermediary authentication service that issues tokens to prove user identity to various third-party services, eliminating the need for users to handle multiple credentials while maintaining security through centralized token management
Solution Approach 2:
The patent employs token copies instead of original passwords for authentication. Tokens are generated as copies that can be transmitted and validated across different services without exposing the user's actual credentials. These token copies can be easily revoked or regenerated without affecting other services, providing a secure alternative to password reuse
2Adaptability or versatility
If users manage multiple authentication credentials, then they can access various accounts, but the process becomes time-consuming and difficult
Solution Approach 1:
The patent implements a universal authentication token that serves multiple functions across different services. A single token issued by the intermediary authentication system can be used to access various third-party services without requiring separate authentication for each service. This multi-functional token eliminates the need for users to manually authenticate with each service individually, significantly reducing authentication time while maintaining access to multiple accounts
3Ease of operation
If users choose easy-to-remember passwords, then authentication becomes simpler, but security becomes vulnerable to breaches
Solution Approach 1:
The patent uses an intermediary authentication service that handles the complexity of secure credential management. Users interact with a simplified token-based interface rather than managing complex passwords directly. The intermediary service generates and manages secure tokens that are both simple for users to handle and secure for services, bridging the gap between ease of use and security
Solution Approach 2:
The patent employs short-lived tokens that are easily generated and discarded, replacing the need for permanent, complex passwords. These tokens can be easily created by the intermediary service and automatically expire or be revoked, providing a secure authentication mechanism that is simpler for users to manage than long, complex passwords while maintaining high security through their limited lifespan
Data Source
AI summary
A method is disclosed that includes: receiving, by an identity provider computing system, a user token and user device information from a third-party provider, whereby the user token is associated with a user of the identity provider computing system and the user device information is associated with a user device of the user; identifying, by the identity provider computing system, related user activity based on the user device information; and authenticating, by the identity provider computing system, the user based on the user token and the related user activity indicating that the user used the user device in another authenticated transaction within a past predefined time period.


