Multi-Entity Token Generator for Unified Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional keyfobs are inconvenient and pose security concerns when users have accounts with multiple financial institutions, as they need to carry and manage multiple devices for authentication.

Innovation Solution

A token generator, such as a keyfob, that stores authentication entity identification information and can generate tokens in synchronization with multiple authentication entities, allowing users to access computers associated with different entities by routing authentication requests through the appropriate entity for validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a user has accounts with multiple financial institutions and uses conventional keyfobs, then each institution issues its own keyfob for authentication, but the user must physically carry and manage multiple keyfobs which is inconvenient and poses security concerns

Engineering Contradiction:
Improveauthentication securityVSAvoidconvenience of carrying keyfobs
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines multiple keyfob functionalities into a single device. The keyfob is configured with multiple authentication entity identification information and can generate tokens for multiple different authentication entities, eliminating the need to carry separate keyfobs for each financial institution while maintaining security through synchronized token generation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The keyfob is designed to perform multiple authentication functions for different entities. It stores identification information for multiple authentication entities and can generate valid tokens for each entity by receiving their respective challenge values and computing synchronized responses, making a single device universally applicable across multiple financial institutions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If conventional keyfobs are used for multiple authentication entities, then each entity requires its own keyfob with dedicated authentication mechanisms, but this increases device complexity and management burden

Engineering Contradiction:
Improvecompatibility with multiple entitiesVSAvoidnumber of keyfobs to manage
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the functionality of multiple entity-specific keyfobs into a single device. The keyfob contains storage for multiple authentication entity identification information and implements token generation logic that can handle challenges from any of the stored entities, reducing the number of devices from N (one per entity) to 1.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The keyfob dynamically adapts its behavior based on which authentication entity is initiating the challenge. It receives challenge values from different entities, identifies the appropriate entity based on the challenge, and generates the corresponding token using the synchronized algorithm specific to that entity, allowing flexible multi-entity support without dedicated hardware for each.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8763105B1Keyfob for use with multiple authentication entities
Publication Date: 2014.06.24 INTUIT INC
  • US8763105B1 patent drawing
  • US8763105B1 patent drawing
  • US8763105B1 patent drawing

AI summary

A token generator such as a keyfob is used to access the computer of an authentication entity different from the authentication entity that issued the token generator. The token generator stores authentication entity identification information identifying the authentication entity that issued the token generator. The token generator causes a user computer to transmit an authentication request including such authentication entity identification information together with a token generated in synchronization with the authentication entity issuing the token generator, so that the authentication request can be routed to the appropriate authentication entity that issued the keyfob for validation. The authentication request can be sent directly to the authentication entity that issued the token generator. The authentication request can also be sent to the authentication entity that issued the token generator via another authentication entity to which the user computer attempts to access.