Bootstrap Authentication for Mobile Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices and other untrusted or limited-capability devices are susceptible to phishing attacks due to simplified user interfaces that lack visual cues, making it unsafe to enter trusted security credentials, and often do not support two-factor authentication.

Innovation Solution

A bootstrap authentication method where a user authenticates on a primary device with trusted credentials and receives a one-time password or token tied to the mobile device, allowing secure access without entering credentials directly on the mobile device, using automated or manual processes like NFC or QR codes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users enter trusted security credentials directly on mobile devices, then ease of operation is improved, but security reliability deteriorates due to phishing susceptibility

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a bootstrap authentication mechanism that acts as an intermediary between the user's trusted credentials and the mobile device. Instead of entering credentials directly on the mobile device, the system uses a bootstrap token generated from trusted credentials on a secure device, which then authenticates the mobile device without exposing the actual credentials. This mediator approach resolves the contradiction by enabling ease of operation on mobile devices while maintaining security reliability through the intermediary authentication process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into two distinct phases: (1) bootstrap authentication using a token generated from trusted credentials on a secure device, and (2) subsequent authentication using the bootstrap token on the mobile device. This segmentation separates the security-critical credential entry from the convenience-oriented mobile access, allowing each phase to optimize for its specific goal without compromising the other.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If mobile devices use simplified user interfaces, then ease of operation is improved, but security reliability deteriorates due to lack of visual cues

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The bootstrap authentication mechanism serves as an intermediary that eliminates the need for visual verification cues on the mobile device interface. By using a token-based approach where the mobile device presents a bootstrap token rather than traditional credentials, the system maintains simplified mobile interfaces while achieving security through the intermediary authentication protocol, which verifies the token's validity without requiring complex visual verification elements.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If two-factor authentication is implemented on all devices, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the two-factor authentication requirement from the mobile device itself and relocates it to a separate bootstrap device. The mobile device only needs to store and present the bootstrap token, while the complex two-factor authentication process occurs on the bootstrap device during the initial token generation. This extraction resolves the contradiction by achieving security reliability through two-factor authentication without adding complexity to the mobile device.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10009355B2Bootstrapping user authentication on devices
Publication Date: 2018.06.26 AMAZON TECH INC
  • US10009355B2 patent drawing
  • US10009355B2 patent drawing
  • US10009355B2 patent drawing

AI summary

Disclosed are various embodiments that facilitate bootstrapping authentication of a user at a first device using a second device. The second device is authenticated for access to a user account via a first security credential. A second security credential is received by the second device. The second security credential is then sent to the first device. Subsequently, the second security credential is received from the first device, and the first device is authenticated for access to the user account. The second device includes visual cues to indicate a network page is legitimate, while the first device excludes visual cues to indicate the network page is legitimate.