Mobile Device Authentication Using Trusted Server Link
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for authentication and authorization are cumbersome, expensive, and inadequate, relying on specialized devices that add complexity and cost, and require users to carry multiple devices and remember multiple PINs, with limited flexibility and standardization.
Innovation Solution
A system and method utilizing a mobile wireless communication device for authentication and authorization, where the device is registered with a trusted server, allowing users to establish a wireless communication link, receive identifying information, and authenticate through a user-programmable memory that stores security credentials, enabling secure transactions without the need for multiple devices or complex challenge-response dialogs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If special-purpose security devices with microprocessors and cryptographic keys are used, then authentication security is improved, but device complexity and cost increase
Solution Approach 1:
The patent applies universality by enabling mobile communication devices to serve multiple purposes: their primary communication function plus authentication and authorization functions. The device uses existing components (processor, memory, communication interface) to perform security functions, eliminating the need for dedicated security devices while maintaining security requirements.
Solution Approach 2:
The patent merges the authentication functionality into the mobile communication device itself, combining what were previously separate functions (communication and security authentication) into a single integrated device. This eliminates the need for users to carry separate security devices while maintaining authentication security.
2Adaptability or versatility
If multiple specialized security devices are carried for different purposes, then authentication coverage is improved, but ease of operation deteriorates
Solution Approach 1:
The mobile communication device is designed to provide universal authentication capability across multiple systems and services. By storing multiple credentials and using the device's existing communication interface, it can authenticate to various authorized systems without requiring users to carry multiple specialized devices or remember multiple PINs.
3Ease of operation
If dedicated security devices with limited computing power are used, then security portability is improved, but adaptability deteriorates
Solution Approach 1:
The mobile communication device provides adaptable authentication capabilities by leveraging its existing processing power and memory to handle various authentication protocols and challenge-response dialogs. The device can dynamically generate responses to different authentication challenges from multiple authorized systems without requiring specialized hardware for each system.
4Reliability
If expensive special-purpose security systems are installed, then authentication security is improved, but cost increases
Solution Approach 1:
The mobile communication device performs authentication operations autonomously using its own processing capabilities, cryptographic functions, and secure memory. The device independently generates challenge responses and manages security credentials without requiring expensive external security hardware or specialized authentication systems at the service provider end.
Solution Approach 2:
The patent uses the mobile device's existing cryptographic capabilities to generate and verify authentication credentials, replacing the need for expensive dedicated security hardware. The authentication security relies on software-based cryptographic operations performed by the mobile device's processor rather than specialized security processors.
Data Source
AI summary
An authorization and authentication system utilizing a mobile communication device. The authentication and authorization system enables a trusted server, in conjunction with a user controlled mobile communication device (which has been registered with the trusted site), to authorize a transaction carried out at a transaction management system. An identity of the user is authenticated by a verification that the user is in possession of the mobile communication device. In this way, the transaction management system is able to effectuate an authorized transaction with confidence that the authorization was from the user and not a third party. In variations, the authentication is a multi-factor authentication, i.e., the user must both possess the mobile communication device and information, e.g., a password.


