Mobile Authentication App Using Barcode Scanning for Secure Multi-App Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote access authentication methods, such as static passwords and dedicated hardware strong authentication tokens, are inadequate due to security risks, user inconvenience, and high costs, particularly when needing to access multiple applications.

Innovation Solution

A system utilizing a user's existing mobile device, equipped with authentication software, that generates dynamic security values using a secret key and dynamic variables, with a trusted third-party authentication server managing secret keys, allowing seamless access to multiple applications without sharing secrets across applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated hardware strong authentication tokens are used, then security level is significantly higher than static passwords, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity levelVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted third-party authentication server as an intermediary to manage secret keys. The server stores secret keys securely and provides them to mobile devices only when needed for authentication, eliminating the need for each device to store multiple secrets locally. This reduces device complexity while maintaining high security through the centralized trusted intermediary.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses software-based authentication on mobile devices that replicates the security functionality of dedicated hardware tokens. By copying the essential authentication capability to widely available mobile devices through software, the system achieves high security without requiring specialized hardware, thus reducing device complexity and cost.

Inventive Principle:
Principle #26Copying

2Reliability

If manual data entry on authentication token keypad is required, then security is maintained, but ease of operation deteriorates when large amounts of data must be entered

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical keypad entry system with automated electronic data capture using the mobile device's camera to scan barcodes. This substitution eliminates manual typing while maintaining security through the use of secret keys stored on the authentication server, significantly improving ease of operation for large data entries.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent performs preliminary action by pre-generating authentication credentials as barcodes that contain encoded authentication data. Users simply scan these pre-prepared barcodes rather than manually entering data, and the authentication server has already prepared the necessary secret key material, enabling secure automated authentication without manual input.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If OTPs are displayed on token and manually copied to PC, then authentication is achieved, but ease of operation deteriorates due to additional user actions required

Engineering Contradiction:
Improveauthentication securityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the manual copy-paste mechanism with automated barcode scanning. The mobile device's camera captures the barcode displayed on the PC screen, and the authentication application automatically extracts and transmits the authentication data to the server, eliminating the need for manual copying while maintaining authentication security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent merges the authentication token functionality directly into the mobile device by installing authentication software on it. This combines the display, data capture, and transmission functions into a single integrated system, eliminating the need for separate manual operations between token and PC while maintaining secure authentication.

Inventive Principle:
Principle #5Merging (Combining)

4Adaptability or versatility

If multiple applications share the same secret key, then authentication across applications is enabled, but security risks increase

Engineering Contradiction:
Improvemulti-application accessVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the secret key management by storing different secret keys for different applications on the authentication server. Each application has its own dedicated secret key that is provided to the mobile device only when that specific application requires authentication. This segmentation enables multi-application access while preventing security risks associated with key sharing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication server acts as an intermediary that manages and distributes different secret keys to the mobile device based on which application is being accessed. Instead of the device storing multiple secrets that could be compromised, the server selectively provides only the necessary secret key for the current authentication context, enabling versatile access while maintaining security isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2885904B1User-convenient authentication method and apparatus using a mobile authentication application
Publication Date: 2018.04.25 ONESPAN INT GMBH
  • EP2885904B1 patent drawingFigure 1
  • EP2885904B1 patent drawingFigure 2
  • EP2885904B1 patent drawingFigure 3a

AI summary

Methods, apparatus, and systems for securing application interactions are disclosed. Application interactions may be secured by, at a user authentication device, capturing a signal emitted by an access device encoded with an authentication initiating message including an application identifier, decoding the signal and obtaining the authentication initiating message, retrieving the application identifier, presenting a human interpretable representation of the application identity to the user, obtaining user approval to generate a response message available to a verification server, generating a dynamic security value using a cryptographic algorithm that is cryptographically linked to the application identity, and generating a response message including the generated dynamic security value; making the response message available to a verification server; and, at the verification server, receiving the response message, verifying the response message including verifying the validity of the dynamic security value, and communicating the result of the verification of the response message to the application.