Mobile Device Authentication Key Replacement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for managed mobile devices in enterprise networks face usability issues while maintaining security, particularly when using smartphones, as they often require additional peripherals or multiple PINs/passwords, compromising user-friendliness.

Innovation Solution

A method employing a mediation platform for authentication that uses a combination of user credentials (identifier and password) and device authentication through a unique device identifier and communication key, with automatic key replacement, ensuring secure access without additional user input, except for initial key requests which can be handled via alternative devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-factor authentication using chip card certificates is implemented for mobile devices, then security is improved, but device complexity and ease of operation deteriorate due to required peripherals and additional user actions

Engineering Contradiction:
Improveauthentication securityVSAvoiduser-friendliness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the second authentication factor (communication key) from external peripherals like chip cards and embeds it directly into the mobile device's persistent memory. This eliminates the need for external card readers and physical chip cards, maintaining security while improving ease of operation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent merges the user credentials authentication with device authentication into a unified process. The communication key stored in the mobile device is automatically used during authentication without requiring separate user actions, combining multiple security factors into a seamless user experience.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If multiple passwords or PINs are required for authentication, then security is improved, but ease of operation deteriorates due to increased user input requirements

Engineering Contradiction:
Improveauthentication securityVSAvoiduser-friendliness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mobile device automatically provides the second authentication factor (communication key) from its persistent memory during the authentication process. The device serves itself by presenting the stored key without requiring the user to manually input multiple passwords or PINs, thus maintaining security while improving ease of operation.

Inventive Principle:
Principle #25Self-service

3Reliability

If device identifier and communication key are transmitted during authentication, then authentication reliability is improved, but vulnerability to man-in-the-middle attacks increases without additional protective measures

Engineering Contradiction:
Improveauthentication accuracyVSAvoidman-in-the-middle attack risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The communication key is pre-stored in the mobile device's persistent memory before the authentication process begins. This preliminary preparation ensures that the key is already available and protected when needed, preventing interception during transmission and mitigating man-in-the-middle attacks while maintaining authentication accuracy.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2723111B1Multiple factor authentification for mobile end devices
Publication Date: 2017.12.06 DEUTSCHE TELEKOM AG
  • EP2723111B1 patent drawingFigure 1
  • EP2723111B1 patent drawingFigure 2

AI summary

The method involves authenticating user of mobile terminals (1,1') by using user characteristic identifier and personal password authentication confirming identity. The affiliation of mobile terminal to the user is identified. A communication key is maintained in a persistent memory of the mobile terminal. The valid key is communicated from the memory to an exchange platform (2) only upon reading of correct entry of the user identifier, so that valid communication key is then replaced by a new communication key with the completion of the authentication process.