Token-Based Device Authentication via Trusted Identifier

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Password-based authentication is cumbersome, insecure, and prone to unauthorized access, as users often struggle to remember complex passwords and are vulnerable to hacking, with passwords providing identification rather than reliable authentication.

Innovation Solution

A computer network system that generates a token with identification information, which is encrypted and transmitted securely, allowing a second device with a trusted identifier to authenticate a first device, eliminating the need for manual input and enhancing security by linking the token to a trustworthy identifier.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If password-based authentication is used, then user identification is provided, but security is compromised and user convenience deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a token as an intermediary element that bridges the server and the user device. The token contains identification information and is transferred through a trusted second device, serving as a mediator that enables secure authentication without requiring users to directly handle complex passwords or credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the manual password entry mechanism with an automated token-based system. Instead of users mechanically typing passwords, the system uses automated token generation, transmission, and verification processes, substituting the manual mechanical interaction with an automated electronic system.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If complex passwords are required, then security level is improved, but memorization burden increases and user compliance decreases

Engineering Contradiction:
Improvepassword securityVSAvoidmemorization effort
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent creates a copy of the identification information within the token structure. Instead of requiring users to remember complex passwords, the system generates a token that contains encoded identification data, which can be automatically transmitted and verified without user memorization.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs authentication automatically using the token and trusted identifier without requiring user intervention for password management. The user simply needs to possess the device with the trusted identifier, and the system handles the complex authentication process itself.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If passwords are used for authentication, then identification is provided, but vulnerability to hacking and unauthorized access increases

Engineering Contradiction:
Improveauthentication simplicityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary actions by generating the token with embedded identification information before the actual authentication process. The token is created and stored in advance on the user's device, and the association with the trusted identifier is established beforehand, enabling secure authentication without exposing credentials during the login process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system takes preliminary anti-action by using the trusted identifier to verify the authenticity of the token before accepting authentication. This preliminary verification prevents unauthorized access by ensuring that only tokens associated with legitimate trusted identifiers can be used for authentication.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10623394B2Device authentication
Publication Date: 2020.04.14 ACCENTURE GLOBAL SERVICES LTD
  • US10623394B2 patent drawing
  • US10623394B2 patent drawing
  • US10623394B2 patent drawing

AI summary

The present invention relates to a computer network that provides secure authentication. The computer network comprises a server operable to generate a token comprising identification information; a first device to be authenticated, the first device being operable to receive the token; a second device associated with a trusted identifier, the second device being operable to retrieve the token from the first device and associate the token with the trusted identifier to authenticate the first device at the server.