Mobile App Authentication via Device ID and Email Token
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communications devices face data loss issues when users switch or wipe devices, particularly in PIN messaging applications, due to the lack of server-based data backup, leading to password fatigue and insecurity from reused passwords.
Innovation Solution
A method and system for automatic user identification and authentication using a unique device identifier and e-mail address, which creates a registration ID and authentication token, allowing devices to automatically register and access backed-up data without requiring user input, thus preserving device data across device changes or wipes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a server-based account system is implemented for data backup, then data preservation across device changes is improved, but password fatigue and security risks increase
Solution Approach 1:
The patent extracts the authentication burden from the user by removing the need for manual password creation and management. The system automatically generates authentication tokens and manages credentials behind the scenes, allowing users to access their data without dealing with passwords directly.
Solution Approach 2:
The system performs self-service authentication by automatically managing credential storage, token generation, and verification processes. The server handles authentication autonomously using device identifiers and stored credentials, eliminating the need for user intervention in password management.
2Reliability
If manual authentication with user IDs and passwords is required, then security is improved, but user convenience and ease of access deteriorate
Solution Approach 1:
The patent introduces authentication tokens as an intermediary between the user's device identifier and the server's credential verification system. These tokens enable automatic authentication without requiring users to manually enter passwords, thus maintaining security while improving convenience.
Solution Approach 2:
The system replaces the mechanical process of manual password entry and verification with an automated electronic authentication mechanism. Device identifiers and cryptographic tokens substitute for traditional username/password interactions, enabling seamless authentication.
3Productivity
If PIN messaging uses unique device identifier as transport address, then direct device-to-device communication is improved, but data vulnerability when device is switched or wiped increases
Solution Approach 1:
The patent implements preliminary data backup to the server before device switching or wiping occurs. The system proactively synchronizes messaging data, contacts, and settings to the server, ensuring data preservation is already in place before any device issue arises.
Solution Approach 2:
The system creates copies of messaging data, contacts, and settings on the server as a backup. This copying mechanism ensures that data exists in multiple locations (device and server), protecting against data loss when the device is switched or wiped.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Automatic identification and authentication of a user of a mobile application entails receiving from the wireless communications device a unique device identifier and an e-mail address corresponding to the wireless communications device, associating a registration identifier with the unique device identifier and the e-mail address, generating an authentication token, and communicating the authentication token and the registration identifier to the wireless communications device. This technology obviates the need for the user to remember and enter a user ID and password to access backed-up application data on a server. This is particularly useful for instant messaging applications, e.g. PIN messaging, in which the unique device identifier is used to identify the user and is also the transport address. Once registered, the user who has switched to a new device or has wiped his existing device, can restore contacts or other application data from the server based on the registration identifier.