Mobile Device Authentication via Visual Pairing Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges in authenticating themselves on public, untrusted devices without exposing their sensitive information, as these devices may be compromised with viruses or malware, and often lack a full user interface or web browser, making it difficult to enter credentials securely.

Innovation Solution

A system that uses a mobile computing device controlled by the user to authenticate with an authentication server, generating and capturing pairing tokens visually or audibly, allowing access to content on a target computing device without directly entering credentials into the potentially untrusted device, thereby associating physical security with information security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users authenticate directly on public, untrusted devices, then access to content is enabled, but sensitive information is exposed to potential malware

Engineering Contradiction:
Improveauthentication accessVSAvoidinformation security risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trusted intermediary device (mobile computing device) that mediates between the user and the untrusted target device. The mobile device receives credentials from the user, authenticates them through a secure channel, and presents authentication tokens to the target device without exposing sensitive information directly on the untrusted device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the authentication logic from the untrusted target device and relocates it to the user's trusted mobile device. Credentials and sensitive authentication data are processed on the mobile device rather than being entered into or stored on the untrusted target device, removing the harmful exposure risk.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If users enter credentials directly into untrusted devices, then authentication is completed, but devices lacking full user interface or web browser become difficult to use

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent makes the authentication system universal by enabling any target device (regardless of whether it has a full user interface, web browser, or specialized display) to work with the user's mobile device. The mobile device adapts to different target device capabilities through various pairing methods (visual pairing tokens, audio signals, NFC) and presents appropriate interfaces to the user accordingly.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If authentication tokens are generated and exchanged between devices, then secure access is achieved, but additional hardware or complex pairing mechanisms are required

Engineering Contradiction:
Improvesecurity protectionVSAvoidpairing mechanism complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements self-service authentication where the mobile device automatically handles credential collection, authentication token generation, and exchange with the target device without requiring manual configuration or additional hardware. The system uses the mobile device's existing camera, audio capabilities, or NFC to automatically establish pairing and complete authentication.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the parameters of authentication by using time-limited pairing tokens with specific formats (visual codes, audio signals) that can be captured by standard mobile device sensors. This transforms the authentication process into something that can be performed with existing mobile device capabilities rather than requiring specialized hardware.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9405889B2Device, method, and system for augmented reality security
Publication Date: 2016.08.02 INTEL CORP
  • US9405889B2 patent drawing
  • US9405889B2 patent drawing
  • US9405889B2 patent drawing

AI summary

Devices and methods for authenticating a user of a mobile computing device to a content server include establishing a communication session between a target computing device and the content server that is identified by a session ID. The target computing device generates a pairing token using the session ID, which pairing token may be a two-dimensional bar code such as a quick response (“QR”) code, and presents the pairing token to the mobile computing device. The mobile computing device captures the pairing token and authenticates the user of the mobile computing device to an authentication server. The target computing device receives an authentication token from the authentication server in response to the mobile computing device successfully authenticating the user to the authentication server. The target computing device accesses content on the content server using the authentication token. Other embodiments are described and claimed.