Mobile Device Authentication via Visual Pairing Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges in authenticating themselves on public, untrusted devices without exposing their sensitive information, as these devices may be compromised with viruses or malware, and often lack a full user interface or web browser, making it difficult to enter credentials securely.
Innovation Solution
A system that uses a mobile computing device controlled by the user to authenticate with an authentication server, generating and capturing pairing tokens visually or audibly, allowing access to content on a target computing device without directly entering credentials into the potentially untrusted device, thereby associating physical security with information security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users authenticate directly on public, untrusted devices, then access to content is enabled, but sensitive information is exposed to potential malware
Solution Approach 1:
The patent introduces a trusted intermediary device (mobile computing device) that mediates between the user and the untrusted target device. The mobile device receives credentials from the user, authenticates them through a secure channel, and presents authentication tokens to the target device without exposing sensitive information directly on the untrusted device.
Solution Approach 2:
The patent extracts the authentication logic from the untrusted target device and relocates it to the user's trusted mobile device. Credentials and sensitive authentication data are processed on the mobile device rather than being entered into or stored on the untrusted target device, removing the harmful exposure risk.
2Reliability
If users enter credentials directly into untrusted devices, then authentication is completed, but devices lacking full user interface or web browser become difficult to use
Solution Approach 1:
The patent makes the authentication system universal by enabling any target device (regardless of whether it has a full user interface, web browser, or specialized display) to work with the user's mobile device. The mobile device adapts to different target device capabilities through various pairing methods (visual pairing tokens, audio signals, NFC) and presents appropriate interfaces to the user accordingly.
3Object-affected harmful factors
If authentication tokens are generated and exchanged between devices, then secure access is achieved, but additional hardware or complex pairing mechanisms are required
Solution Approach 1:
The patent implements self-service authentication where the mobile device automatically handles credential collection, authentication token generation, and exchange with the target device without requiring manual configuration or additional hardware. The system uses the mobile device's existing camera, audio capabilities, or NFC to automatically establish pairing and complete authentication.
Solution Approach 2:
The patent changes the parameters of authentication by using time-limited pairing tokens with specific formats (visual codes, audio signals) that can be captured by standard mobile device sensors. This transforms the authentication process into something that can be performed with existing mobile device capabilities rather than requiring specialized hardware.
Data Source
AI summary
Devices and methods for authenticating a user of a mobile computing device to a content server include establishing a communication session between a target computing device and the content server that is identified by a session ID. The target computing device generates a pairing token using the session ID, which pairing token may be a two-dimensional bar code such as a quick response (“QR”) code, and presents the pairing token to the mobile computing device. The mobile computing device captures the pairing token and authenticates the user of the mobile computing device to an authentication server. The target computing device receives an authentication token from the authentication server in response to the mobile computing device successfully authenticating the user to the authentication server. The target computing device accesses content on the content server using the authentication token. Other embodiments are described and claimed.


