Web Service Authentication Using Device Tokens and Biometrics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing web service authentication methods are vulnerable to fraud from keylogging programs, compromising server security and efficiency.
Innovation Solution
A system and method using a smart device app with a secure token and biometric authentication to verify user identity, allowing secure web service access without entering credentials directly on the web page.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional username and password authentication is used, then ease of operation is improved, but security is worsened due to vulnerability to keylogging fraud
Solution Approach 1:
The patent introduces an intermediary authentication mechanism using device-specific tokens and biometric verification. Instead of directly entering credentials on the web page (which exposes them to keyloggers), the system uses a trusted device as an intermediary that holds the token and performs biometric authentication locally. This intermediary approach eliminates direct credential entry while maintaining ease of use through automated token presentation.
Solution Approach 2:
The patent replaces the mechanical keyboard input system (typing username and password) with biometric authentication (fingerprint, facial recognition, or other physiological traits). This substitution eliminates the vulnerability to keylogging while maintaining user convenience, as biometric authentication is as easy as the previous method but secure against credential theft.
2Reliability
If server systems take extra precautions to detect malicious parties, then security is improved, but computing efficiency is worsened
Solution Approach 1:
The patent performs security verification in advance by binding device identifiers to user accounts during registration and authentication. The server pre-validates that the token originates from a registered device before processing the authentication request. This preliminary action eliminates the need for complex real-time fraud detection during login, maintaining security while improving processing efficiency.
Solution Approach 2:
The patent uses device identifiers (such as hardware IDs or device tokens) as immutable copies of the physical device's identity. These identifiers serve as reliable fingerprints that the server can verify without complex analysis. By copying and verifying these stable device characteristics, the system achieves secure authentication with minimal computational overhead compared to analyzing behavioral patterns or multiple verification steps.
Data Source
AI summary
A system and method provides access to one or more web services by capturing a human perceptible rendering on a separate device.


