Cross-Channel Device Binding via SessionID Linking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile device security systems fail to effectively prevent unauthorized access across different communication channels, allowing malicious users to masquerade as authorized users and access sensitive information by using different channels, such as apps and web browsers, without being detected.

Innovation Solution

Implementing a cross-channel device binding system that generates and links unique identifiers across multiple communication channels, such as InMobile™ for app channels and InBrowser™ for web channels, using a SessionID to associate and verify device IDs, thereby distinguishing authorized from unauthorized devices and reducing the risk of unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If channel-specific device IDs are used separately for each communication channel, then each channel can independently verify device authorization, but malicious users can masquerade as authorized users by using different channels without detection

Engineering Contradiction:
Improvedevice authorization verificationVSAvoidunauthorized access across channels
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent merges separate channel-specific device IDs into a unified cross-channel device binding framework. By linking the app device ID and browser device ID through a common binding relationship, the system combines previously independent authentication channels into a coordinated security system that can detect and prevent cross-channel masquerading attacks.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal device binding mechanism that works across multiple communication channels (app channel and browser channel). The binding relationship established through the link request serves multiple functions: it binds device IDs across channels, enables cross-channel authorization verification, and provides a foundation for detecting unauthorized access attempts regardless of which channel is used.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Object-affected harmful factors

If device IDs are linked across multiple channels, then unauthorized masquerading can be detected and prevented, but the system complexity increases due to additional binding and verification mechanisms

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidcross-channel binding system
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements preliminary binding action by establishing device ID linkages across channels before unauthorized access attempts occur. The binding relationship is created in advance through the link request mechanism, so that when authorization verification is needed, the system can immediately check the pre-established binding relationships without complex real-time analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a binding relationship as an intermediary concept that connects device IDs across different channels. This intermediary mechanism simplifies the overall system architecture by providing a standardized way to represent cross-channel associations, making the verification process more manageable despite involving multiple channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If cross-channel device binding is implemented, then comprehensive device authorization can be verified across all channels, but the verification process requires additional link requests and binding operations

Engineering Contradiction:
Improvecross-channel authorization verificationVSAvoiddevice binding and verification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs binding operations in advance through link requests, so that when authorization verification is needed, the binding relationships are already established and ready for immediate checking. This preliminary action reduces the time required during actual verification operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables devices to self-register and self-bind across channels through automated link request processing. The binding mechanism operates autonomously based on device identification information, reducing manual intervention and accelerating the verification process while maintaining comprehensive cross-channel authorization checks.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3381166B1Systems and methods for cross-channel device binding
Publication Date: 2021.04.28 ACCERTIFY INC
  • EP3381166B1 patent drawingFigure 1
  • EP3381166B1 patent drawingFigure 2
  • EP3381166B1 patent drawingFigure 3

AI summary

A system facilitates secure communication between an authorized user device and two or more servers via two or more channels that are associated with the respective servers. For each communication channel, the system receives a device identifier for the authorized user device and links the device identifiers together via another identifier, thereby allowing the system to recognize that the different device identifiers identify the same authorized user device. The system can identify an unauthorized device masquerading as the authorized user device by determining that a communication from the unauthorized device does not include another identifier linking the two or more device identifiers and/or by determining that a device identifier computed during the registration process is different from a linked identifier.