Out-of-band Browser Session Authentication via Barcode
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges in securely accessing online accounts due to vulnerabilities in password management, including the use of weak passwords, password theft by malware, and the inconvenience of entering complex PIN numbers or passwords across different devices.
Innovation Solution
A method and system that generates a unique identifier for a client device, encodes it into a bar code or audio signal, and allows a second device to decode and authenticate, enabling secure access without directly entering passwords on unfamiliar or untrusted computing systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users enter passwords directly on unfamiliar computing systems, then authentication can be completed, but security vulnerabilities increase due to malware and phishing risks
Solution Approach 1:
The patent introduces a trusted second device as an intermediary in the authentication process. Instead of entering passwords directly on potentially compromised first devices, users authenticate through a trusted second device that displays verification codes or captures authentication data, thereby mediating the authentication process and eliminating direct password entry on untrusted systems.
Solution Approach 2:
The patent extracts the password entry function from the first device (potentially compromised system) and relocates it to the second device (trusted system). By taking out the sensitive authentication input operation from the untrusted environment and performing it in a trusted environment, the system eliminates the security vulnerability associated with direct password entry on unfamiliar computing systems.
2Reliability
If users store passwords in password managers or on personal computers, then strong passwords can be used, but accessibility issues arise when using other computers
Solution Approach 1:
The patent enables the second device (trusted device) to serve multiple functions: it acts as a password manager, an authentication device, and a portable credential storage. By making the trusted device universal for authentication purposes across multiple first devices, users can maintain strong passwords locally on their trusted device while accessing accounts on any first device without needing to manually input or transfer passwords.
Solution Approach 2:
The patent creates a copy of the authentication capability from the trusted second device to the first device through the exchange of verification codes or authentication tokens. Instead of copying passwords (which would be insecure), the system copies the authentication authority, allowing the first device to be authenticated without actually containing or transmitting the password.
3Reliability
If complex PIN numbers are used for authentication, then security is improved, but user convenience decreases due to manual entry requirements
Solution Approach 1:
The patent implements self-service authentication where the second device automatically performs the authentication verification without requiring manual entry of complex PINs or passwords by the user. The system generates and verifies authentication codes automatically, allowing the authentication process to serve itself rather than requiring manual user input of complex credentials.
Solution Approach 2:
The patent replaces the mechanical process of manually typing complex PINs or passwords with automated electronic verification. Instead of the user physically entering authentication credentials through a keyboard or input interface, the system uses automated code generation, display, and verification through the second device, substituting the mechanical entry process with an automated electronic authentication mechanism.
Data Source
AI summary
Systems and methods provide a user with secure access to a web site at a first client device without having to enter login information, such as a username and password, at that device. For example, the first device may request access to user information from a server system. The server may generate a session ID, associate it with the first device, and encode it into a bar code that is displayed at the first device. Using camera functions, a second client device may identify and decode the bar code to determine the session ID. The login information may be entered into the second device in order to establish a secure connection with the server. The second device may transmit the session ID to the server system. The server may identify the first client device based on the common session ID and transmit the requested user information to the first device.


