Automated Mobile Authentication via Localized Context Criteria
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current multi-factor authentication methods are cumbersome and require significant infrastructure, limiting their adoption beyond niche user bases, and raise privacy concerns due to the need for location data storage on central servers.
Innovation Solution
A system that leverages modern mobile devices for automated, unobtrusive authentication using location awareness and contextual information to provide a second factor of authentication, allowing for automated permission responses based on pre-defined criteria, eliminating the need for repeated user input and reducing infrastructure requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware security tokens are used for multi-factor authentication, then authentication security is improved, but device complexity and infrastructure requirements increase significantly
Solution Approach 1:
The patent replaces physical hardware tokens with software-based authentication mechanisms that replicate the security functionality of hardware tokens using mobile devices. The system uses software applications on smartphones to generate and verify authentication codes, eliminating the need for specialized hardware infrastructure while maintaining security requirements.
Solution Approach 2:
The patent substitutes mechanical/physical hardware tokens with electronic/software-based authentication systems. Instead of requiring physical devices with screens displaying codes, the system uses mobile device software applications that can generate, display, and transmit authentication information electronically through communication protocols.
2Device complexity
If software-based tokens on mobile devices are used, then infrastructure requirements are reduced, but user convenience deteriorates due to repeated manual code transcription
Solution Approach 1:
The patent implements pre-configured authentication profiles and automated response mechanisms that are set up in advance. The system stores authentication credentials and automation rules locally on mobile devices, allowing the device to automatically respond to authentication requests without requiring users to manually transcribe codes each time, thus preparing the authentication mechanism beforehand.
Solution Approach 2:
The patent enables mobile devices to autonomously handle authentication processes through locally stored automation criteria and pre-configured profiles. The device automatically determines whether to grant or deny authentication requests based on stored rules, eliminating the need for repeated manual user intervention while maintaining security controls.
3Measurement precision
If location data is stored on central servers for authentication, then authentication accuracy is improved, but user privacy concerns increase due to data security risks
Solution Approach 1:
The patent extracts location processing functionality from central servers and relocates it to mobile devices. The system stores automation criteria and location data locally on the user's mobile device rather than on centralized servers, removing the vulnerable central storage point while maintaining the ability to perform location-based authentication decisions.
Solution Approach 2:
The patent implements localized data processing where location information and automation criteria are processed and stored locally on the mobile device. Each device independently evaluates authentication requests based on its own stored location data and criteria, rather than relying on centralized server storage, thus distributing data security responsibilities to individual devices.
Data Source
AI summary
Techniques are disclosed relating to automating permission requests, e.g., in the context of multi-factor authentication. In some embodiments a mobile device receives permission requests that specify sets of one or more automation criteria. In some embodiments, the mobile device prompts a user for a response to permission requests when the criteria are not met and automatically responds to permission requests (e.g., without requiring user input) when the criteria are met. Disclosed techniques may increase authorization security while reducing user interaction for multi-factor authentication, in some embodiments.


