Mobile Authentication via Caller ID and Time-Limited Access Numbers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The high cost and frequent replacement of token devices for access control, as well as the inconvenience of lost or forgotten devices, create a significant expense and accessibility issue for companies and users.

Innovation Solution

A system utilizing a cellular telephone to authenticate users through caller ID and password, generating a time-limited access number that can be used to access restricted resources, reducing the need for physical token devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If token devices are distributed to all employees and customers for secure access, then access security is improved, but the cost and device replacement expenses increase significantly

Engineering Contradiction:
Improveaccess securityVSAvoidnumber of token devices
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent replaces physical token devices with virtual copies implemented as software applications on mobile devices. The authentication token is copied from the server to the user's mobile device, eliminating the need for expensive physical hardware tokens while maintaining security. This is achieved through the token generation application that receives and stores authentication tokens digitally.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent substitutes the mechanical/physical token device system with an electronic software-based system. Instead of relying on physical hardware tokens that require distribution and replacement, the system uses software applications on mobile devices that can be remotely provisioned and updated, eliminating manufacturing and logistics costs associated with physical tokens.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If physical token devices are used for authentication, then secure access is achieved, but the system becomes complex and requires periodic replacement

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the mobile device universal by using it for multiple purposes: as a communication device, as an authentication token, and as a secure storage medium. This multi-functionality eliminates the need for dedicated physical token devices, reducing system complexity while maintaining authentication security through the same device users already carry and interact with daily.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If token devices are lost or forgotten, then access to restricted resources is blocked, but replacing devices creates inconvenience and additional costs

Engineering Contradiction:
Improveaccess controlVSAvoidaccess convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables self-service recovery of lost authentication tokens. When a mobile device is lost or stolen, the user can remotely wipe the device or request a new token through the system, and the authentication token can be re-provisioned to a replacement device without requiring physical replacement of hardware tokens or complex administrative procedures. The system automatically manages token lifecycle including generation, distribution, and revocation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8213583B2Secure access to restricted resource
Publication Date: 2012.07.03 WORKDAY INC
  • US8213583B2 patent drawing
  • US8213583B2 patent drawing
  • US8213583B2 patent drawing

AI summary

A system may generate an access number, provide the access number to a user via a telephone call, and provide the access number to an authentication server. The system may regulate access by the user to a restricted resource based on the access number provided to the user and the access number provided to the authentication server.