Device Locator Authentication via Cloud Credential Binding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current device locator systems are vulnerable to being disabled by thieves, making it difficult to locate or remotely erase lost or stolen mobile devices, as they can easily turn off location features, erase devices, or reset them to circumvent security measures.
Innovation Solution
Associating a mobile device's hardware identifier with cloud-based account credentials, which requires authentication to enable or disable the Find My Device mode, ensuring that only authorized users can reactivate or use the device after it has been erased or reset.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device locator mode is enabled on a mobile device, then the device can be located and tracked, but a thief or unauthorized person can disable the mode by turning off location features, erasing the device, or resetting it
Solution Approach 1:
The system performs preliminary authentication before allowing the device locator mode to be disabled. When a user attempts to disable Find My Device, the system challenges them for credentials associated with the device's hardware identifier beforehand, preventing unauthorized disabling before it occurs.
Solution Approach 2:
The system introduces an intermediary authentication mechanism between the user and the device locator mode. A server acts as a mediator that verifies credentials against the hardware identifier before permitting mode changes, blocking unauthorized access attempts.
2Loss of information
If a device is erased or reset to remove personal information, then data security is improved, but the device locator mode is disabled making the device unlocatable
Solution Approach 1:
The system requires preliminary authentication before allowing device erasure or reset operations. When a user attempts to erase the device, they must first provide valid credentials verified by the server, ensuring authorized users can erase while preventing thieves from erasing to disable tracking.
Solution Approach 2:
The system applies preliminary anti-action by blocking the erasure operation unless authentication succeeds. This prevents the harmful effect of unauthorized erasure that would disable the device locator, while allowing legitimate erasure by authorized users.
3Ease of operation
If Find My Device mode is disabled without authentication, then ease of operation is improved, but security is worsened as unauthorized users can easily disable tracking
Solution Approach 1:
The system introduces an intermediary authentication step between the user and the Find My Device mode. When attempting to disable the mode, the system mediates through a credential verification process with the server, maintaining security while allowing legitimate users to disable the mode when needed.
Data Source
AI summary
A device locator mode or find my device (FMD) mode can allow a lost, stolen, or misplaced mobile device to be located. The FMD mode can be enabled or disabled on a mobile device. Sometimes thieves or unauthorized parties attempt to disable the FMD mode. To prevent this, the mobile device can transmit a unique device identifier to a remote server. The remote server can link the device identifier to a cloud-based user account associated with the user of the mobile device. Before an FMD mode is disabled on the mobile device, before the content or settings can be erased, and/or before a mobile device is permitted to be activated/reactivated, a user of the mobile device can be challenged for the credentials of the cloud-based user account. If valid credentials are provided, FMD can be disabled, the content or settings can be reset, and/or the device can be activated/reactivated.


