Bootstrap Authentication for Mobile Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices and other untrusted or limited-capability devices are susceptible to phishing attacks due to simplified user interfaces that lack visual cues, making it unsafe to enter trusted security credentials, and often do not support two-factor authentication.
Innovation Solution
A bootstrap authentication method where a user authenticates on a primary device with trusted credentials and receives a one-time password or token tied to the mobile device, allowing secure access without entering credentials directly on the mobile device, using automated or manual processes like NFC or QR codes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users enter trusted security credentials directly on mobile devices, then ease of operation is improved, but security reliability deteriorates due to phishing susceptibility
Solution Approach 1:
The patent introduces a bootstrap authentication mechanism that acts as an intermediary between the user's trusted credentials and the mobile device. Instead of entering credentials directly on the mobile device, the system uses a bootstrap token generated from trusted credentials on a secure device, which then authenticates the mobile device without exposing the actual credentials. This mediator approach resolves the contradiction by enabling ease of operation on mobile devices while maintaining security reliability through the intermediary authentication process.
Solution Approach 2:
The authentication process is segmented into two distinct phases: (1) bootstrap authentication using a token generated from trusted credentials on a secure device, and (2) subsequent authentication using the bootstrap token on the mobile device. This segmentation separates the security-critical credential entry from the convenience-oriented mobile access, allowing each phase to optimize for its specific goal without compromising the other.
2Ease of operation
If mobile devices use simplified user interfaces, then ease of operation is improved, but security reliability deteriorates due to lack of visual cues
Solution Approach 1:
The bootstrap authentication mechanism serves as an intermediary that eliminates the need for visual verification cues on the mobile device interface. By using a token-based approach where the mobile device presents a bootstrap token rather than traditional credentials, the system maintains simplified mobile interfaces while achieving security through the intermediary authentication protocol, which verifies the token's validity without requiring complex visual verification elements.
3Reliability
If two-factor authentication is implemented on all devices, then security reliability is improved, but device complexity increases
Solution Approach 1:
The patent extracts the two-factor authentication requirement from the mobile device itself and relocates it to a separate bootstrap device. The mobile device only needs to store and present the bootstrap token, while the complex two-factor authentication process occurs on the bootstrap device during the initial token generation. This extraction resolves the contradiction by achieving security reliability through two-factor authentication without adding complexity to the mobile device.
Data Source
AI summary
Disclosed are various embodiments that facilitate bootstrapping authentication of a user at a first device using a second device. The second device is authenticated for access to a user account via a first security credential. A second security credential is received by the second device. The second security credential is then sent to the first device. Subsequently, the second security credential is received from the first device, and the first device is authenticated for access to the user account. The second device includes visual cues to indicate a network page is legitimate, while the first device excludes visual cues to indicate the network page is legitimate.


