Mobile Device Authentication via Unique Data Strings

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional electronic transactions rely heavily on Auxiliary Security Verification Information (ASVI) which is vulnerable to theft and compromise, leading to fraud and identity theft, as users are required to provide sensitive information for authentication, and existing methods lack robust and user-friendly additional authentication mechanisms.

Innovation Solution

The method involves using mobile devices to authenticate users by generating a unique data string that is sent to both the user's mobile device and the vendor, ensuring that the user's identity is verified through physical possession of the device, thereby reducing reliance on ASVI and enhancing security against fraud.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If ASVI information is used for authentication, then user identity verification is possible, but the system becomes vulnerable to theft and compromise

Engineering Contradiction:
Improveauthentication securityVSAvoidfraud and identity theft vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an authentication service provider as an intermediary between the user and the vendor. This mediator generates and manages temporary authentication credentials (data strings) that are transmitted through multiple parties without exposing the core identification information. The intermediary architecture prevents direct exposure of sensitive user data while enabling secure verification, thus resolving the contradiction between authentication capability and security vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of using the user's actual identification information directly, the system creates temporary copies in the form of data strings that represent the user's identity for authentication purposes only. These copied credentials can be transmitted and verified without revealing the original sensitive information, thereby maintaining authentication reliability while eliminating the vulnerability to theft of personal data.

Inventive Principle:
Principle #26Copying

2Reliability

If traditional ASVI verification is used, then authentication can be performed, but user convenience is reduced due to requiring card swiping and identification provision

Engineering Contradiction:
Improvetransaction securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication service provider enables self-service authentication where the user's mobile device automatically generates and transmits the data string without requiring manual card swiping or identification provision. The system performs verification automatically in the background, allowing users to complete transactions with minimal effort while maintaining strong security through the intermediary authentication process.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If ASVI information is stored by vendors and transaction handlers, then authentication verification is enabled, but the information becomes vulnerable to theft and compromise

Engineering Contradiction:
Improveauthentication capabilityVSAvoiddata theft and compromise risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication verification function from the vendor and transaction handler systems, centralizing it in a dedicated authentication service provider. This extraction removes sensitive authentication data from multiple vulnerable storage points and concentrates security management in a single controlled environment, enabling authentication capability while eliminating the widespread data storage vulnerability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system uses temporary data string copies instead of storing actual ASVI information at vendors or transaction handlers. These ephemeral credentials enable authentication verification without requiring persistent storage of sensitive user data at multiple locations, thus providing adaptability while reducing theft and compromise risk.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11087317B2Authentication and verification services for third party vendors using mobile devices
Publication Date: 2021.08.10 ALCATEL LUCENT SA
  • US11087317B2 patent drawing
  • US11087317B2 patent drawing
  • US11087317B2 patent drawing

AI summary

A method to provide authentication services to third party vendors by a service provider hosting an authentication, authorization and accounting (AAA) server or a similar device that can authenticate users for some other service. This method enables easy and substantially error-free end-user authentication, which forms the basis for enabling electronic transactions (e.g., web-based) that are less vulnerable to fraud.