Cross-Device Authentication via Verification Code Relay

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face annoyance and security risks due to the need for frequent password entry on computing devices, often leading to the use of simple passwords that are easily compromised, and the inconvenience of managing multiple device authentications.

Innovation Solution

A method and system that allows users to authenticate on a first computing device using a second device on which they are already authenticated, by transmitting an authentication request and acceptance key between devices, eliminating the need for manual password entry on the first device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If passwords are required for authentication, then security is maintained, but user convenience deteriorates due to frequent manual entry

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication by sending a verification code to a pre-registered device (mobile phone) where the user has already been authenticated. This preliminary action on the trusted device eliminates the need for repeated password entry on the current device, resolving the contradiction between security and convenience.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism using a verification code sent to a mobile device as a mediator between the user and the system. This intermediary approach allows authentication without direct password entry, maintaining security while improving convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If simple passwords are used to improve ease of entry, then authentication convenience improves, but security deteriorates due to easy guessing

Engineering Contradiction:
Improvepassword entry easeVSAvoidpassword security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the password from the authentication process entirely. Instead of requiring password entry, the system uses a verification code sent to a mobile device, effectively taking out the vulnerable password element while maintaining authentication security and improving entry ease.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent substitutes the mechanical password entry system with an automated verification code delivery system. The verification code is automatically sent to the user's mobile device and validated by the server, replacing the manual password typing mechanism and eliminating the security-convenience trade-off.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If passwords are required on multiple devices, then security is maintained, but time consumption increases due to repeated authentication

Engineering Contradiction:
Improvemulti-device securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a universal authentication approach where a single verification code sent to the user's mobile device can authenticate across multiple devices. This multi-functional verification mechanism eliminates the need for separate password entry on each device, maintaining security while reducing authentication time.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If frequent password changes are required to improve security, then reliability improves, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system provides self-service authentication through the verification code mechanism. The user automatically receives verification codes on their mobile device without needing to manually update or change passwords, making the authentication process easier while maintaining security through the self-service nature of the system.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10764278B2Authentication on a computing device
Publication Date: 2020.09.01 GOOGLE LLC
  • US10764278B2 patent drawing
  • US10764278B2 patent drawing
  • US10764278B2 patent drawing

AI summary

Systems and/or methods provide a user of a first computing device with the ability to authenticate themselves on a remotely provided process or service using a second computing device on which the user is already authenticated. For example, the techniques of this disclosure provide a user with the ability to securely log into a remotely provided service or application (such as e-mail, cloud computing service, etc.) on a first computing device (e.g., a desktop computer, laptop, tablet, etc.) using a second computing device (e.g., mobile phone) on which the user is already logged into the service or application, without requiring manual entry of authentication information on the first computing device.