Local Device Authentication via Multi-Device Code Decryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing encryption and network access techniques are vulnerable to security breaches, compromising the integrity of transmitted messages and network security.

Innovation Solution

A method involving a user device transmitting authentication credentials to a server, which then sends encrypted codes to secondary devices via a local network (Bluetooth, intranet, NFC, or mesh) for decryption, with the decrypted codes combined and transmitted back to the server for access authorization, ensuring a common network connection is maintained.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional single-point authentication is used, then the authentication process is simple, but security vulnerabilities exist and can compromise network security

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into multiple independent components: primary authentication server, secondary authentication servers, multiple user devices, and multiple secondary devices. Each segment performs a specific authentication function, and the combination of segments creates a more secure multi-point authentication system that resolves the vulnerability of single-point authentication while maintaining manageable complexity through modular design

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements nested authentication layers where secondary authentication mechanisms are embedded within the primary authentication framework. The system nests multiple levels of verification (primary credential validation, secondary device presence verification, encrypted code exchange) where each layer provides additional security without requiring a completely separate system, thus improving reliability while controlling complexity

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If multiple authentication credentials are required, then security is improved, but user input time and operational complexity increase

Engineering Contradiction:
Improveauthentication securityVSAvoiduser input time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication actions by pre-establishing trusted relationships between secondary devices and the authentication server before the actual access request. Secondary devices pre-register their credentials and public keys, so when authentication is needed, the system can quickly verify presence and exchange encrypted codes without requiring users to manually input multiple credentials, thus maintaining high security while reducing user input time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service authentication mechanisms where secondary devices automatically perform verification tasks without requiring user intervention. The system uses device-to-device encrypted communication and automatic credential validation, allowing the authentication process to serve itself through automated protocols rather than requiring users to manually provide multiple authentication inputs, thereby improving security while minimizing time loss

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12537689B2Local device authentication system
Publication Date: 2026.01.27 CAPITAL ONE SERVICES LLC
  • US12537689B2 patent drawing
  • US12537689B2 patent drawing
  • US12537689B2 patent drawing

AI summary

Various embodiments are generally directed to provide a semi-local authentication scheme. A server can transmit one or more encryption mechanisms to a user device, which in turn can transmit the encrypted mechanisms to one or more secondary devices associated with the user device, where the user device and the secondary devices share a local connection. The secondary devices can transmit the one or more encrypted mechanism utilizing one or more one or more decryption mechanisms supplied by the server, and then transmit the result of the decryption, e.g. decrypted codes, back to the user device, which in turn can then transmit a final decrypted code or codes to the server. Upon confirming receipt of the decryption from the user device, the server can authorize access (via the user device) to one or more devices, networks, applications, and/or components.