Combined User Authentication With Device and App Integrity Checks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods fail to ensure the integrity of electronic devices and applications, leaving them vulnerable to fraudulent usage and misuse.

Innovation Solution

A method that integrates device and application integrity checks into the authentication process by using an identity provider server to verify the integrity of electronic devices and applications before authenticating users, utilizing a Smart Security Management Server (SSMS) to assess device and application integrity and return authentication information that includes both user authentication and integrity verification results.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If only user authentication is performed, then the authentication process is simple and fast, but the system is vulnerable to fraudulent usage and credential copying

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines user authentication with device integrity verification into a single unified authentication process. The authentication server performs both functions simultaneously by receiving authentication credentials and device integrity information together, then validating both aspects before granting access. This merging approach enhances security by ensuring both user identity and device trustworthiness without significantly increasing process complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs device integrity verification as a preliminary action before completing user authentication. The authentication server checks device integrity information (such as hardware identifiers, software versions, or security certificates) before finalizing the authentication decision. This preliminary check prevents fraudulent access even when user credentials are compromised, as the device must also pass integrity verification.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If device and application integrity checks are added to authentication, then fraudulent usage is reduced, but the authentication process becomes more complex and time-consuming

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Device integrity verification is performed as a preliminary action during the authentication process, allowing parallel processing of credential validation and device checking. This approach enables security enhancements without significantly increasing total authentication time, as both checks occur concurrently rather than sequentially.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system utilizes device-provided integrity information (such as embedded security credentials or self-reported device states) that the device generates and maintains autonomously. This self-service approach reduces the computational burden on the authentication server and minimizes additional time required for verification, as the device already maintains its own integrity metrics.

Inventive Principle:
Principle #25Self-service

3Reliability

If comprehensive integrity verification is implemented, then service misuse is prevented, but the authentication system requires more information and processing

Engineering Contradiction:
Improveservice protectionVSAvoidinformation processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication server merges user credential validation with device integrity verification into a single processing workflow. Both authentication credentials and device integrity information are received, validated, and processed together in one unified decision-making process, rather than as separate independent checks. This reduces overall system complexity by consolidating multiple verification functions into a single integrated process.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication server is designed to perform multiple functions simultaneously: validating user credentials, verifying device integrity, checking application legitimacy, and making access decisions. This multi-functional approach consolidates what would otherwise require multiple separate systems into a single universal authentication authority, reducing overall system complexity while maintaining comprehensive security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3507735B1Combined user authentication and device/application integrity check
Publication Date: 2025.07.02 KOBIL SYST
  • EP3507735B1 patent drawingFigure 1
  • EP3507735B1 patent drawingFigure 2~3
  • EP3507735B1 patent drawingFigure 4

AI summary

A method is disclosed comprising receiving an authentication request related to authentication of a user of an electronic device towards a server of a service provider (120); checking or causing checking of an integrity of the electronic device (130) and/or of an integrity of at least one application of the electronic device (131); performing or causing authentication of the user of the electronic device (130); and returning or causing returning of authentication information towards the server of the service provider (120); wherein at least a part of the authentication information and/or the returning of at least a part of the authentication information is indicative of the user having been authenticated by the authentication, and wherein at least a part of the authentication information and/or the returning of at least a part of the authentication information represents that the electronic device (130) and/or the at least one application (131) has/ have been considered integer by the checking. Further methods and related apparatuses, computer programs and a system are disclosed.