Location-Aware Mobile Authentication Automation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current two-factor authentication (TFA) methods are cumbersome and require significant infrastructure, which limits their adoption beyond niche user bases, and raise privacy concerns due to the need for location data transmission to central servers.
Innovation Solution
A method that uses location awareness on mobile devices to automate permission responses for authentication requests, eliminating the need for manual input and reducing infrastructure requirements, by pairing devices with authenticating services and allowing automation based on learned locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware tokens are used for two-factor authentication, then security is improved, but device complexity and infrastructure requirements increase significantly
Solution Approach 1:
The patent uses software-based tokens that replicate the functionality of hardware tokens on mobile devices. Instead of requiring physical hardware tokens with complex infrastructure, the system creates virtual copies of the authentication token within the mobile device's operating system, maintaining security while eliminating hardware complexity
Solution Approach 2:
The patent replaces the mechanical hardware token system with a software-based authentication mechanism. The physical token display and manual transcription process is substituted with automated push notifications and in-app code generation, eliminating the need for hardware infrastructure while maintaining the two-factor authentication security
2Device complexity
If software-based tokens on mobile devices are used, then infrastructure requirements are reduced, but user convenience deteriorates due to manual code retrieval and transcription
Solution Approach 1:
The authentication system performs self-service by automatically generating and displaying the authentication code within the mobile device's existing application interface. The system serves itself by utilizing the mobile device's own display and notification mechanisms, eliminating the need for users to manually retrieve codes from separate hardware tokens or perform manual transcription operations
Solution Approach 2:
The patent merges the authentication code display functionality with the existing mobile device interface and application ecosystem. Instead of separating the code generation from the user interface, the system integrates the authentication code delivery directly into the mobile device's display and notification systems, combining multiple functions into a single unified interface that improves user convenience
3Measurement precision
If location data is transmitted to central servers for authentication, then authentication accuracy is improved, but privacy concerns increase due to data storage on third-party servers
Solution Approach 1:
The patent extracts the location data processing from the central server and places it directly on the mobile device. Instead of transmitting location information to third-party servers for processing, the system performs location-based authentication decisions locally within the mobile device, eliminating the need to store sensitive location data on external servers while maintaining authentication accuracy
Solution Approach 2:
The mobile device acts as an intermediary that processes location data locally before any authentication decision is made. The device serves as an intermediate layer that handles location information locally, preventing direct transmission of sensitive location data to central servers while still enabling accurate location-based authentication through the device's built-in location services
Data Source
AI summary
Systems and methods for authenticating defined user actions over a computer network. An authentication service receives an authentication request from an authenticating service to perform an action on behalf of a user. The authentication service then sends a permission request to a mobile device associated with the user, asking the user whether or not the action should be allowed. The user sends a permission response via the mobile device to the authentication service, granting or denying the action. The user may automate future similar responses so long as at least one automation criterion is met (e.g., the physical location of the mobile device), eliminating the need to manually provide a response to future permission requests. Information necessary to determine whether the automation criterion is met is stored locally on the mobile device.


