Deep-Link Authentication for Automatic One-Time Passcode Parsing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional two-factor authentication methods using one-time passcodes are inconvenient for users, as they require manual entry and are prone to typographical errors, leading to security risks and user frustration.
Innovation Solution
A method utilizing deep-links on communication devices to automatically parse and transmit one-time passcodes, eliminating the need for manual entry and enhancing security by verifying user possession of the device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If one-time passcodes are used for two-factor authentication, then security is improved, but user convenience deteriorates due to manual entry requirements
Solution Approach 1:
The system automatically transmits the one-time passcode from the communications application to the host application without requiring user intervention for copying or manual entry. The deep link mechanism enables the passcode to self-transmit through automated parsing and submission, eliminating the manual operations that reduce user convenience while maintaining security.
Solution Approach 2:
The deep link serves as an intermediary mechanism that bridges the communications application (receiving passcode) and the host application (verifying passcode). This intermediary enables automatic passcode transmission by embedding the passcode in a structured link format that can be automatically parsed and submitted, resolving the contradiction between security and convenience.
2Reliability
If manual passcode entry is required, then authentication verification is achieved, but typographical errors increase leading to user frustration and security risks
Solution Approach 1:
The system performs automatic passcode extraction and submission without human intervention. The host application automatically parses the deep link to extract the passcode and submits it for verification, eliminating typographical errors that occur during manual entry while maintaining authentication verification integrity.
Solution Approach 2:
The manual mechanical process of copying and pasting or typing the passcode is replaced with an automated electronic process. The system uses automated link parsing and programmatic submission to replace human manual entry operations, thereby eliminating typographical errors while maintaining verification reliability.
3Reliability
If users must navigate to email to retrieve passcode, then authentication process is completed, but time consumption increases
Solution Approach 1:
The passcode is pre-positioned within the deep link structure in the communications application, ready for immediate automated extraction. This preliminary preparation eliminates the need for users to navigate to email and manually retrieve the passcode, as the passcode is already in place and can be automatically submitted through the deep link mechanism.
Solution Approach 2:
The patent merges the passcode delivery mechanism (communications application) with the authentication verification mechanism (host application) through the deep link. This consolidation eliminates the separate step of navigating to email to retrieve the passcode, as the entire authentication flow is integrated into a single automated process that reduces time consumption while maintaining completion reliability.
Data Source
AI summary
A method and system for authentication through deep-links is provided. A communication device can provide a credential to a remote server computer as part of an authentication process. The remote server computer can challenge the communication device by transmitting a deep-link containing a one-time passcode to the communication device. The communication device can activate and parse the deep-link to determine the one-time passcode. The one-time passcode can be transmitted back to the remote server computer by the communication device. The remote server computer can verify that received one-time passcode matches the sent one-time passcode in order to complete the authentication process.


