Connected Authentication Device Using Mobile SSO Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in securely accessing multiple online resources with different login credentials, which can be cumbersome and pose security risks, and there is a challenge in proving possession of a mobile device to an electronic interface not connected to it.

Innovation Solution

An electronic connected device, such as a key fob with a processor, network interface, and memory, is used to store and transmit tokens for accessing online resources, utilizing a Short-Range Radio (SRR) connection and geographic proximity verification to authenticate the user's device and computer, allowing secure access without manual credential entry.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users use different login credentials for each online resource, then security is improved, but ease of operation deteriorates due to the need to remember multiple credentials

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a copy of the user's identity credentials in the form of a digital token stored on a mobile device. This token replicates the authentication functionality of traditional login credentials, allowing the mobile device to serve as a portable authentication source that eliminates the need to remember multiple passwords while maintaining security through token-based verification

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a token server and digital token as an intermediary between the user and online resources. Instead of directly presenting multiple different credentials, the user presents a single token that the server validates against stored credential information, simplifying the authentication process while maintaining security through server-side verification

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If users use the same login credentials for multiple online resources, then ease of operation is improved, but security deteriorates due to the risk of unauthorized access

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication system into distinct components: the user's mobile device containing a token, a token server storing credential information, and the online resource systems. This segmentation allows the user to have a single simplified interface (the token) while the backend maintains separate security validations for different resources, thus providing ease of use without compromising security

Inventive Principle:
Principle #1Segmentation

3Reliability

If users prove device possession through connection, then authentication reliability is improved, but device complexity increases due to connection requirements

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical/connection-based authentication system with a wireless communication system. Instead of requiring physical connections or complex hardware interactions to prove device possession, the system uses wireless token transmission and geographic proximity verification, simplifying the user experience while maintaining or enhancing authentication reliability through location-based validation

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10135805B2Connected authentication device using mobile single sign on credentials
Publication Date: 2018.11.20 CELLCO PARTNERSHIP INC
  • US10135805B2 patent drawing
  • US10135805B2 patent drawing
  • US10135805B2 patent drawing

AI summary

Systems and methods for device-based authentication are disclosed. In some implementations, a device receives a Single Sign On PIN from a backend server. The device transmits, to a token server, the Single Sign On PIN and credentials of a subscriber identity module (SIM) to request a token for accessing a network resource via a computer different from the device. The token is associated with a user account. The device receives the token from the token server. The device stores the token at a local memory of the device.