Co-Located Secondary Devices for Low-Latency Cookie Theft Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems are inefficient and cumbersome in preventing cookie theft, particularly when using two-factor authentication, which causes latency and inconvenience due to the need for user intervention.

Innovation Solution

Implementing a mechanism where a physically co-located secondary client device acts as an authentication device to verify service requests, using cryptographic keys and short-range communication to ensure the primary and secondary devices are within proximity, thereby authenticating service requests without additional latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If two-factor authentication is used to prevent cookie theft, then security is improved, but user convenience deteriorates due to additional latency and intervention requirements

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by establishing a trusted relationship between primary and secondary devices before cookie theft can occur. The secondary device is pre-configured with authentication credentials and automatically validates service requests without requiring user intervention at the moment of authentication, thus maintaining security while eliminating the latency and inconvenience of traditional two-factor authentication

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The secondary device performs self-service authentication by automatically validating service requests using pre-configured credentials. Instead of requiring user intervention to provide verification codes or approve requests, the system enables the secondary device to independently authenticate requests, thereby improving user convenience while maintaining security

Inventive Principle:
Principle #25Self-service

2Reliability

If traditional authentication methods are used, then security is improved, but processing speed deteriorates due to additional verification steps

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

Authentication credentials are pre-configured on the secondary device before actual service requests occur. This preliminary setup eliminates the need for real-time verification delays, allowing the system to quickly validate requests by comparing against pre-stored credentials while maintaining strong security

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple authentication devices are used, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into two distinct functional components: a primary device that generates service requests and a secondary device that validates them. This segmentation allows each device to have a specific, simplified role, reducing the complexity burden on individual devices while maintaining overall system security through the distributed authentication architecture

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12457105B2Using co-located secondary devices to protect against cookie theft
Publication Date: 2025.10.28 GOOGLE LLC
  • US12457105B2 patent drawing
  • US12457105B2 patent drawing
  • US12457105B2 patent drawing

AI summary

A method includes receiving, by a service provider platform, a service request from a first client device, and a first instance of an authentication token associated with the service request and generated by the first client device. The service provider platform may further receive, from a second client device, a second instance of the authentication token associated with the service request and generated by the first client device. Responsive to determining that the first instance of the authentication token matches the second instance of the authentication token, the service request is processed by the service provider platform.