Cross-Device Authentication via Verification Code Relay
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face annoyance and security risks due to the need for frequent password entry on computing devices, often leading to the use of simple passwords that are easily compromised, and the inconvenience of managing multiple device authentications.
Innovation Solution
A method and system that allows users to authenticate on a first computing device using a second device on which they are already authenticated, by transmitting an authentication request and acceptance key between devices, eliminating the need for manual password entry on the first device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If passwords are required for authentication, then security is maintained, but user convenience deteriorates due to frequent manual entry
Solution Approach 1:
The system performs preliminary authentication by sending a verification code to a pre-registered device (mobile phone) where the user has already been authenticated. This preliminary action on the trusted device eliminates the need for repeated password entry on the current device, resolving the contradiction between security and convenience.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism using a verification code sent to a mobile device as a mediator between the user and the system. This intermediary approach allows authentication without direct password entry, maintaining security while improving convenience.
2Ease of operation
If simple passwords are used to improve ease of entry, then authentication convenience improves, but security deteriorates due to easy guessing
Solution Approach 1:
The patent extracts the password from the authentication process entirely. Instead of requiring password entry, the system uses a verification code sent to a mobile device, effectively taking out the vulnerable password element while maintaining authentication security and improving entry ease.
Solution Approach 2:
The patent substitutes the mechanical password entry system with an automated verification code delivery system. The verification code is automatically sent to the user's mobile device and validated by the server, replacing the manual password typing mechanism and eliminating the security-convenience trade-off.
3Reliability
If passwords are required on multiple devices, then security is maintained, but time consumption increases due to repeated authentication
Solution Approach 1:
The patent implements a universal authentication approach where a single verification code sent to the user's mobile device can authenticate across multiple devices. This multi-functional verification mechanism eliminates the need for separate password entry on each device, maintaining security while reducing authentication time.
4Reliability
If frequent password changes are required to improve security, then reliability improves, but ease of operation deteriorates
Solution Approach 1:
The system provides self-service authentication through the verification code mechanism. The user automatically receives verification codes on their mobile device without needing to manually update or change passwords, making the authentication process easier while maintaining security through the self-service nature of the system.
Data Source
AI summary
Systems and/or methods provide a user of a first computing device with the ability to authenticate themselves on a remotely provided process or service using a second computing device on which the user is already authenticated. For example, the techniques of this disclosure provide a user with the ability to securely log into a remotely provided service or application (such as e-mail, cloud computing service, etc.) on a first computing device (e.g., a desktop computer, laptop, tablet, etc.) using a second computing device (e.g., mobile phone) on which the user is already logged into the service or application, without requiring manual entry of authentication information on the first computing device.


