Token-Based Authentication System for Secure Multi-System Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in securely and efficiently authenticating and authorizing user access across multiple systems, as they often require insecure and cumbersome data transmission of sensitive information, limiting network performance and user access capabilities.
Innovation Solution
A method and system that verify user authenticity and generate tokens for access, allowing secure transmission of a token portion between primary and secondary sites, enabling users to access multiple systems without repeated administrative tasks and reducing data transmission insecurity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If sensitive user information is directly transmitted between primary and secondary systems, then user authentication and authorization can be achieved, but security is compromised and network performance is limited
Solution Approach 1:
The patent introduces a token as an intermediary element that mediates between the user and the primary system. Instead of directly transmitting sensitive user information, the system generates a token that represents the user's authentication state. This token is transmitted between systems, allowing verification without exposing underlying sensitive data, thus improving security while maintaining network efficiency.
Solution Approach 2:
The patent creates a copy of the authentication state in the form of a token. Rather than transmitting the original sensitive user information multiple times across different systems, a token copy is generated that contains sufficient information for verification purposes. This copying approach reduces the security risks associated with transmitting sensitive data while preserving the necessary authentication functionality.
2Adaptability or versatility
If separate transmission is performed for each secondary system, then user access to multiple systems is enabled, but the process becomes cumbersome and complex
Solution Approach 1:
The patent implements a universal token that can be used across multiple secondary systems to access the primary system. Instead of requiring separate authentication transmissions for each secondary system, the same token serves multiple purposes and can be presented to any authorized secondary system. This multi-functional approach enables users to access multiple systems without repeating the authentication process, reducing complexity while maintaining versatile access capability.
3Reliability
If user information is transmitted repeatedly for each access request, then authentication can be verified, but data transmission security is compromised and network performance decreases
Solution Approach 1:
The patent performs authentication verification in advance by generating a token that encapsulates the user's authentication state. This preliminary authentication action eliminates the need for repeated transmission and verification of sensitive user information for each subsequent access request. The token, once generated, can be reused for multiple access requests within its validity period, significantly reducing network transmission overhead while maintaining authentication verification reliability.
Data Source
AI summary
A method, apparatus, and system are provided for authenticating and authorizing user access to a system. According to one embodiment, a request for authentication and authorization of a user is received from a secondary site on behalf of the user who is seeking to access a primary site via the secondary site via a computer network. The request includes information relating to the user. The user information is then verified for authenticity, including determining whether the user satisfies the criteria for obtaining authentication and authorization as defined by the primary site. If the criteria are satisfied, a token, associated with the user, is generated at the primary site. A portion of the token is transmitted from the primary site to the secondary site on behalf of the user to permit the user to access the primary site via the secondary site, via the computer network.


