LAN-Based Device Authentication via Secure Identifier Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods, particularly two-factor authentication, are vulnerable due to reliance on SMS, which is not encrypted and can be unreliable, and users often reuse passwords across multiple services, making them susceptible to hacking.
Innovation Solution
A method for registering a device with an authentication service that establishes a secure connection over a local area network, obtaining a unique identifier from a registered device, and using this identifier as a credential to enhance security without relying on SMS, allowing for automatic registration and improved user experience.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SMS-based two-factor authentication is used, then device authentication can be achieved, but security is compromised because SMS messages are not encrypted and can be intercepted
Solution Approach 1:
The patent extracts the authentication mechanism from the vulnerable SMS channel and relocates it to a secure local area network connection. The device obtains an identifier from a registered device through a secure LAN connection (wireless or wired) instead of receiving authentication codes via SMS, thereby eliminating the security vulnerability of SMS while maintaining the two-factor authentication framework.
Solution Approach 2:
The patent introduces a registered device as an intermediary that resides on the user's local area network. This intermediary device holds a unique identifier that can be securely obtained by the unregistered device through the LAN connection. The registered device acts as a trusted mediator that enables secure authentication without requiring SMS communication.
2Ease of manufacture
If SMS-based authentication is used, then device registration can be performed, but reliability is reduced due to transmission delays and message loss
Solution Approach 1:
The patent replaces the cellular network messaging mechanism (SMS) with a local area network data transmission mechanism. By substituting the SMS protocol with direct LAN communication (either wireless Wi-Fi or wired Ethernet), the system eliminates the reliability issues associated with cellular message delivery, including transmission delays and message loss, while maintaining ease of implementation through standard network protocols.
3Ease of operation
If users reuse passwords across multiple services, then ease of operation is improved, but security is compromised making users susceptible to hacking
Solution Approach 1:
The patent changes the authentication parameter from password-based (something you know) to device-identifier-based (something you have). By requiring a unique device identifier obtained through secure LAN connection in addition to or instead of passwords, the system maintains user convenience while fundamentally improving security. Users don't need to manage complex unique passwords for each service, but the device-specific identifier provides strong security even if passwords are reused.
4Reliability
If manual authentication processes are used, then security control is maintained, but user experience deteriorates due to complex PIN exchange and one-time tokens
Solution Approach 1:
The patent enables the unregistered device to automatically obtain the unique identifier from the registered device through the local area network without requiring manual user intervention. The authentication process becomes self-service, where the devices communicate autonomously over the secure LAN connection, eliminating the need for users to manually handle PINs, one-time tokens, or complex authentication sequences, thereby dramatically improving user experience while maintaining security.
Data Source
AI summary
A method of registering a device with an authentication service; in which the method comprises the device; establishing a secure connection between the device and a second device: in which the second device is registered with the authentication service; in which the second device is allocated to the user, in which the secure connection comprises one of: a wireless data connection; and a wired data connection over a LAN; in which the method further comprises tire device: obtaining over tire secure connection from the registered device, an identifier uniquely associated with the registered device; providing to tire authentication service a first credential known to the user; and a second credential derived front tire identifier, and requesting registration on tire basis of tire first and second credentials.


