Cross-Channel Device Binding via SessionID Linking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile device security systems fail to effectively prevent unauthorized access across different communication channels, allowing malicious users to masquerade as authorized users and access sensitive information by using different channels, such as apps and web browsers, without being detected.
Innovation Solution
Implementing a cross-channel device binding system that generates and links unique identifiers across multiple communication channels, such as InMobile™ for app channels and InBrowser™ for web channels, using a SessionID to associate and verify device IDs, thereby distinguishing authorized from unauthorized devices and reducing the risk of unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If channel-specific device IDs are used separately for each communication channel, then each channel can independently verify device authorization, but malicious users can masquerade as authorized users by using different channels without detection
Solution Approach 1:
The patent merges separate channel-specific device IDs into a unified cross-channel device binding framework. By linking the app device ID and browser device ID through a common binding relationship, the system combines previously independent authentication channels into a coordinated security system that can detect and prevent cross-channel masquerading attacks.
Solution Approach 2:
The patent creates a universal device binding mechanism that works across multiple communication channels (app channel and browser channel). The binding relationship established through the link request serves multiple functions: it binds device IDs across channels, enables cross-channel authorization verification, and provides a foundation for detecting unauthorized access attempts regardless of which channel is used.
2Object-affected harmful factors
If device IDs are linked across multiple channels, then unauthorized masquerading can be detected and prevented, but the system complexity increases due to additional binding and verification mechanisms
Solution Approach 1:
The patent implements preliminary binding action by establishing device ID linkages across channels before unauthorized access attempts occur. The binding relationship is created in advance through the link request mechanism, so that when authorization verification is needed, the system can immediately check the pre-established binding relationships without complex real-time analysis.
Solution Approach 2:
The patent introduces a binding relationship as an intermediary concept that connects device IDs across different channels. This intermediary mechanism simplifies the overall system architecture by providing a standardized way to represent cross-channel associations, making the verification process more manageable despite involving multiple channels.
3Reliability
If cross-channel device binding is implemented, then comprehensive device authorization can be verified across all channels, but the verification process requires additional link requests and binding operations
Solution Approach 1:
The patent performs binding operations in advance through link requests, so that when authorization verification is needed, the binding relationships are already established and ready for immediate checking. This preliminary action reduces the time required during actual verification operations.
Solution Approach 2:
The system enables devices to self-register and self-bind across channels through automated link request processing. The binding mechanism operates autonomously based on device identification information, reducing manual intervention and accelerating the verification process while maintaining comprehensive cross-channel authorization checks.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system facilitates secure communication between an authorized user device and two or more servers via two or more channels that are associated with the respective servers. For each communication channel, the system receives a device identifier for the authorized user device and links the device identifiers together via another identifier, thereby allowing the system to recognize that the different device identifiers identify the same authorized user device. The system can identify an unauthorized device masquerading as the authorized user device by determining that a communication from the unauthorized device does not include another identifier linking the two or more device identifiers and/or by determining that a device identifier computed during the registration process is different from a linked identifier.