Mobile Device Authentication Key Replacement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for managed mobile devices in enterprise networks face usability issues while maintaining security, particularly when using smartphones, as they often require additional peripherals or multiple PINs/passwords, compromising user-friendliness.
Innovation Solution
A method employing a mediation platform for authentication that uses a combination of user credentials (identifier and password) and device authentication through a unique device identifier and communication key, with automatic key replacement, ensuring secure access without additional user input, except for initial key requests which can be handled via alternative devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multi-factor authentication using chip card certificates is implemented for mobile devices, then security is improved, but device complexity and ease of operation deteriorate due to required peripherals and additional user actions
Solution Approach 1:
The patent extracts the second authentication factor (communication key) from external peripherals like chip cards and embeds it directly into the mobile device's persistent memory. This eliminates the need for external card readers and physical chip cards, maintaining security while improving ease of operation.
Solution Approach 2:
The patent merges the user credentials authentication with device authentication into a unified process. The communication key stored in the mobile device is automatically used during authentication without requiring separate user actions, combining multiple security factors into a seamless user experience.
2Reliability
If multiple passwords or PINs are required for authentication, then security is improved, but ease of operation deteriorates due to increased user input requirements
Solution Approach 1:
The mobile device automatically provides the second authentication factor (communication key) from its persistent memory during the authentication process. The device serves itself by presenting the stored key without requiring the user to manually input multiple passwords or PINs, thus maintaining security while improving ease of operation.
3Reliability
If device identifier and communication key are transmitted during authentication, then authentication reliability is improved, but vulnerability to man-in-the-middle attacks increases without additional protective measures
Solution Approach 1:
The communication key is pre-stored in the mobile device's persistent memory before the authentication process begins. This preliminary preparation ensures that the key is already available and protected when needed, preventing interception during transmission and mitigating man-in-the-middle attacks while maintaining authentication accuracy.
Data Source
Figure 1
Figure 2
AI summary
The method involves authenticating user of mobile terminals (1,1') by using user characteristic identifier and personal password authentication confirming identity. The affiliation of mobile terminal to the user is identified. A communication key is maintained in a persistent memory of the mobile terminal. The valid key is communicated from the memory to an exchange platform (2) only upon reading of correct entry of the user identifier, so that valid communication key is then replaced by a new communication key with the completion of the authentication process.