Token-Based Remote Authentication for Generic User Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing omnichannel systems face challenges in securely authenticating users, particularly in sectors like the air transport industry, where companies do not manage the specific user identities of their customers or suppliers, leading to difficulties in providing secure access to customer data and services without knowing the specific identity of the user.
Innovation Solution
A method and system that uses generic user identification information, such as organization and location, to authenticate devices, generating an identification token via a remote management module, allowing secure access to computer programs without requiring individual user authentication, and ensuring data access is limited to the relevant customer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If individual user authentication is implemented in omnichannel systems, then security is improved, but device complexity and difficulty of operation increase for sectors that do not manage specific user identities
Solution Approach 1:
The patent introduces a remote management module as an intermediary between the device and the authentication system. This module stores registration data and communicates with the server to obtain identification tokens, thereby eliminating the need for the device to directly implement complex individual user authentication while maintaining security through token-based verification
Solution Approach 2:
The patent extracts the authentication logic from the device itself and relocates it to the remote management module and server. The device only needs to store generic identification information and exchange tokens, while the complex verification processes are performed externally by dedicated authentication components
2Reliability
If individual user authentication is required, then access control is improved, but ease of operation deteriorates as users must manually authenticate each time
Solution Approach 1:
The patent implements self-service authentication where the device automatically performs verification by exchanging identification tokens with the server through the remote management module. This eliminates the need for manual user authentication while maintaining secure access control, as the device autonomously completes the authentication process using pre-stored registration data
Solution Approach 2:
The patent performs preliminary registration of devices with the remote management module, storing generic identification information in advance. This pre-configuration enables automatic authentication during subsequent access attempts, eliminating the need for real-time manual user verification while maintaining security
3Ease of operation
If generic user identification is used, then ease of operation is improved, but measurement precision of user identity deteriorates
Solution Approach 1:
The patent segments the identification system into two levels: generic device identification stored in the remote management module for automatic authentication, and specific user identity verification handled by the server through identification tokens. This segmentation allows simple automatic access while maintaining the ability to verify specific user identities when needed
Solution Approach 2:
The server acts as an intermediary that bridges generic device identification and specific user verification. It receives generic identification from the device, issues identification tokens, and can perform additional verification as needed, thereby maintaining both operational simplicity and identity verification precision
Data Source
AI summary
A method of secure communication between a device and a computer program running on a server is disclosed. The method comprising the steps of: sending, from the device to the server, generic user identification information based on a current user account logged into on the device; identifying, by the server, the generic user identification information as corresponding to an allowed entity pre-registered with the server; sending, from the server to a remote management module, an identification token associated with the allowed entity, said remote management module having stored thereon a register of registered devices; running, by the remote management module, a remote action on the device using the stored register entry for that device, wherein the remote action passes the identification token to the device; sending, from the device to the server, the identification token; and allowing the device to access the computer program based at least in part on a match between the identification token sent by the server and the identification token received by the server from the device.


