Device Authorization via Multi-Identifier Fingerprinting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Devices with multiple identifiers face authentication challenges due to ambiguity in retrieving and utilizing unique identifiers, leading to potential authorization issues and device fingerprint mismatch errors, especially in dual SIM devices.

Innovation Solution

A method and system for identifying multiple device identifiers, sorting them according to a predetermined rule, and determining authorization information to ensure secure application access, which includes using a combination of identifiers like IMEIs and MAC addresses to generate a unique device fingerprint.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a device includes multiple device identifiers (e.g., dual SIM devices with multiple IMEIs), then the device functionality and versatility are improved, but authentication reliability and authorization accuracy deteriorate due to ambiguity in identifier selection

Engineering Contradiction:
Improvedevice functionalityVSAvoidauthentication reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by collecting all device identifiers (IMEI1, IMEI2, MAC address) before authorization requests, and pre-generates authorization information for each identifier. This allows the system to be prepared with all possible authorization tokens in advance, eliminating ambiguity during actual authentication operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates multiple copies of authorization information, each tied to a specific device identifier. Instead of using a single identifier for authorization, the system generates separate authorization information copies for each identifier (first authorization information for IMEI1, second authorization information for IMEI2), allowing any copy to validly authenticate the device.

Inventive Principle:
Principle #26Copying

2Measurement precision

If multiple device identifiers are used for authentication, then device identification completeness is improved, but processing complexity and difficulty of managing authorization increases

Engineering Contradiction:
Improvedevice identification completenessVSAvoidauthorization management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a universal authorization approach where multiple device identifiers (IMEI1, IMEI2, MAC address) serve the same authentication function. Each identifier can independently validate device identity, and each has corresponding authorization information that works interchangeably, simplifying the management model despite multiple identifiers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system segments the authorization management by creating distinct authorization information for each device identifier while maintaining a unified authorization framework. Each identifier-authorization pair is handled independently, but all lead to the same authorization outcome, making the complex multi-identifier system manageable through modular segmentation.

Inventive Principle:
Principle #1Segmentation

3Reliability

If device identifiers are retrieved and used for authorization, then device authentication capability is improved, but the risk of device fingerprint mismatch errors and unauthorized access increases

Engineering Contradiction:
Improvedevice authentication capabilityVSAvoiddevice fingerprint mismatch errors
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system applies beforehand cushioning by generating and storing multiple sets of authorization information corresponding to different device identifiers before any authorization requests occur. This preparatory measure cushions against potential fingerprint mismatches by ensuring that if one identifier's authorization fails or becomes invalid, other pre-prepared authorization information can still validate the device.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS11240236B2Methods for authorizing use of an application on a device
Publication Date: 2022.02.01 MASTERCARD INT INC
  • US11240236B2 patent drawing
  • US11240236B2 patent drawing
  • US11240236B2 patent drawing

AI summary

According to an embodiment, there is provided a method for authorizing use of an application on a device. The method includes: identifying a plurality of device identifiers of the device; determining authorization information based on predetermined one or more of the plurality of device identifiers; and determining authorization for use of the application on the device in response to the authorization information.