Mobile App Bypass Login via Installation ID

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Social-networking systems face challenges in efficiently authenticating users on mobile devices and authorizing software applications, particularly when accessing third-party websites, which can lead to increased user friction and security vulnerabilities.

Innovation Solution

The implementation of a unique installation ID system, where a first installation ID is generated and stored on the mobile client device, allowing subsequent authorization of software applications without requiring users to re-enter login credentials, by using a browser cookie or token for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional login authentication is used for each application access, then security is maintained through credential verification, but user friction increases and convenience deteriorates

Engineering Contradiction:
ImproveAuthentication convenienceVSAvoidSecurity verification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication when the application is first installed, storing a unique installation ID and associated authentication token. This preliminary action eliminates the need for repeated login credentials during subsequent application launches, resolving the contradiction by establishing security upfront while enabling convenient future access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of requiring users to repeatedly provide their login credentials, the system creates a copy of the authentication state in the form of a unique installation ID and token. This copy serves as a sufficient proof of authorization for future access, maintaining security while dramatically improving convenience.

Inventive Principle:
Principle #26Copying

2Reliability

If login credentials are required for every application launch, then security is ensured through repeated verification, but user experience deteriorates and time is lost

Engineering Contradiction:
ImproveAuthentication securityVSAvoidLogin time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication is performed in advance during application installation, with the authentication result stored as a unique installation ID and token. This preliminary authentication eliminates the need for time-consuming login processes during each application launch, resolving the contradiction by establishing security upfront while enabling instant future access.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If installation ID system is implemented to bypass login, then user convenience is improved and time is saved, but system complexity increases and security validation becomes more complex

Engineering Contradiction:
ImproveAuthorization simplicityVSAvoidAuthentication system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system introduces a unique installation ID and associated token as an intermediary between the user's login credentials and the authentication system. This intermediary simplifies the authorization process by serving as a straightforward proof of installation and entitlement, while the server validates its authenticity against stored records, resolving the contradiction by simplifying client-side operations while maintaining server-side security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10223758B2Bypass login for applications on mobile devices
Publication Date: 2019.03.05 META PLATFORMS INC
  • US10223758B2 patent drawing
  • US10223758B2 patent drawing
  • US10223758B2 patent drawing

AI summary

In one embodiment, a social-networking system authenticates a user of a mobile device, receives a request from the mobile device to install a software application, transmits data to the mobile device comprising the software application and an installation identifier (ID), receives another request including the installation ID from the mobile device to authorize the software application, evaluates the installation ID for validity, and transmits yet another response to the mobile device in accordance with the evaluation.