Cross-device One-time Password Transfer via Intermediary Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users with visual impairments or reading disabilities face difficulties in accessing one-time-passwords (OTPs) for secure services, as they require manual retrieval and entry from email or messages, which can be cumbersome and time-consuming.

Innovation Solution

Systems and methods for cross-device OTP access, where a mobile device analyzes incoming messages or notifications for OTPs and securely transfers them to a target device via Bluetooth, public-private key mechanisms, or cloud-based authentication, automatically populating the OTP field or copying it to a password manager.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a one-time-password is sent to a user's email or mobile device, then security is improved, but the ease of operation deteriorates because the user must manually retrieve and enter the OTP from email or message

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary system (browser extension or application) that acts as a mediator between the messaging service and the target website. This intermediary automatically detects OTP-containing messages, extracts the OTP, and transfers it to the target device, eliminating the need for manual user intervention while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by automatically performing the OTP retrieval and transfer process without requiring user action. The browser extension or application autonomously monitors for OTP messages, identifies them through pattern recognition, extracts the OTP code, and inputs it into the target website's authentication field.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual OTP entry is required, then security is maintained, but the time required for authentication increases

Engineering Contradiction:
ImprovesecurityVSAvoidtime required for authentication
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-positioning the OTP transfer mechanism in place through browser extensions or applications. When an OTP message arrives, the system has already established the automated transfer pathway, allowing immediate extraction and transmission of the OTP without requiring the user to manually copy and paste the code.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The automated OTP transfer system performs the authentication assistance self-service, continuously monitoring for OTP messages and automatically transferring them when detected. This eliminates the time-consuming manual steps of opening emails, copying OTPs, and pasting them into authentication fields.

Inventive Principle:
Principle #25Self-service

3Reliability

If users with visual impairments use traditional OTP methods, then security authentication is achieved, but the ease of operation significantly deteriorates

Engineering Contradiction:
ImproveauthenticationVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary system (browser extension or application) that acts as a mediator between the messaging service and the target website. This intermediary automatically detects OTP-containing messages, extracts the OTP, and transfers it to the target device, eliminating the need for manual user intervention while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by automatically performing the OTP retrieval and transfer process without requiring user action. The browser extension or application autonomously monitors for OTP messages, identifies them through pattern recognition, extracts the OTP code, and inputs it into the target website's authentication field.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11252145B2Cross-device access to one-time passwords
Publication Date: 2022.02.15 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11252145B2 patent drawing
  • US11252145B2 patent drawing
  • US11252145B2 patent drawing

AI summary

In non-limiting examples of the present disclosure, systems, methods and devices for providing cross-device access to one-time passwords are presented. A user may provide sign-in credentials to a secure service via an application or website user interface. The user may be prompted to authenticate the user's identity by confirming a one-time-password sent from the secure service to a secondary device via an electronic message. The secondary device may analyze received messages, or message notifications, to determine whether they include a one-time-password. If a one-time-password is identified in a received message, the one-time-password may be automatically sent from the secondary device to a target computing device. The one-time-password may be sent securely to the target computing device via Bluetooth, a public-private key process, and/or a cloud-based authentication mechanism. The one-time-password may be automatically inserted into a one-time-password field or copied to a notepad or password manager.