Universal Token Authentication for Consumer Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Consumer applications face difficulties in implementing strong authentication due to the need for multiple authentication devices for various accounts, which is cumbersome and costly, and existing solutions are not easily adaptable for interactions with diverse entities.

Innovation Solution

A centralized or distributed token service infrastructure and credential wallet model that allows a shared token to be used across multiple sites, utilizing a centralized validation service, token lookup service, and mobile devices to manage and validate second-factor credentials, enabling authentication with a single device like a cell phone.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple authentication devices are issued to consumers for different accounts, then authentication security is improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
Improveauthentication securityVSAvoidnumber of authentication devices
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication token that can be used across multiple diverse entities (banks, merchants, service providers). The token contains a identifier that can be validated by any entity in the network, eliminating the need for separate tokens for each account or entity while maintaining strong authentication security across all applications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple authentication devices are issued to consumers for different accounts, then authentication security is improved, but ease of operation worsens

Engineering Contradiction:
Improveauthentication securityVSAvoidconvenience of authentication
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The universal token allows consumers to authenticate with any entity in the network using a single device, greatly improving ease of operation. The token management system automatically handles validation across different entities, so the consumer simply uses the same token for all authentication needs without manual configuration or tracking of multiple devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If a shared token is used across multiple sites, then ease of operation is improved, but adaptability worsens

Engineering Contradiction:
Improveconvenience of authenticationVSAvoidcompatibility with diverse entities
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent introduces a token validation service as an intermediary that enables the shared token to work across diverse entities. The service maintains a registry of authorized entities and validates token identifiers against this registry, allowing a single token to be adapted for use with multiple different entities without compromising security or compatibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP1883782B1Token sharing system and method
Publication Date: 2014.10.15 SYMANTEC INT LTD
  • EP1883782B1 patent drawingFigure 1
  • EP1883782B1 patent drawingFigure 2
  • EP1883782B1 patent drawingFigure 3

AI summary

A scalable system and method for authenticating entities such as consumers to entities with a diverse set of authentication requirements, such as merchants, banks, vendors, other consumers, and so on. An authentication credential such as a token can be shared among several resources as a way to authenticate the credential owner.