Mobile Device Authentication via Session Key and Location Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods for accessing customer data are plagued by issues such as physical presence requirements, infrastructure costs, and vulnerabilities like password mismanagement and data leakage, necessitating a more secure and convenient solution.
Innovation Solution
A system and method utilizing a mobile device-based authentication system that generates a one-time session key, validated through geo-spatial location matching and unique identification, to control access to customer data, ensuring secure access without storing sensitive information on the device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric-based authentication is used, then authentication security is improved, but physical presence requirement and device complexity increase
Solution Approach 1:
The patent replaces traditional mechanical authentication methods (physical presence, smart cards, biometrics) with a mobile device-based authentication system that uses software-based session keys and location verification. The mechanical/physical authentication requirements are substituted with digital credential verification through the mobile device, eliminating the need for physical presence while maintaining security.
Solution Approach 2:
The patent creates a copy of the authentication mechanism through the mobile device session key. Instead of requiring the actual customer to be physically present with their biometric data or smart card, the system generates a temporary session key that acts as a copy of the authentication credential. This session key can be verified remotely without requiring the physical customer, thus resolving the contradiction between security and physical presence requirement.
2Ease of operation
If password-based authentication is used, then ease of operation is improved, but security vulnerabilities and data leakage risk increase
Solution Approach 1:
The patent introduces dynamic session keys that are generated temporarily for each authentication session rather than using static passwords. The session key is created dynamically based on the customer's mobile device location and authentication request. This dynamic approach eliminates the security vulnerabilities of static passwords while maintaining ease of operation, as customers simply need to provide their mobile device for location-based verification.
Solution Approach 2:
The patent introduces a location verification intermediary between the authentication system and the customer. Instead of directly storing and verifying passwords (which creates data leakage risks), the system uses mobile device location data as an intermediary verification mechanism. The location information acts as a mediator that confirms the customer's identity without requiring the system to store sensitive password data, thus eliminating data leakage vulnerabilities while maintaining operational convenience.
3Reliability
If static password and dynamic token authentication is used, then authentication security is improved, but infrastructure cost and operational inconvenience increase
Solution Approach 1:
The patent enables the customer's mobile device to serve as the authentication token itself. Instead of requiring separate hardware tokens that need to be managed, retrieved, and coded, the mobile device uses its existing location services and authentication capabilities to generate and verify session keys. The system leverages the mobile device's inherent features (GPS, processor, display) for authentication, eliminating the need for additional infrastructure hardware and reducing operational inconvenience.
Solution Approach 2:
The patent makes the mobile device universal for authentication purposes. The mobile device serves multiple functions: it acts as the authentication token, provides location verification, displays verification codes, and communicates with the authentication system. This multi-functionality eliminates the need for separate dedicated authentication hardware, reducing infrastructure costs while maintaining high security through the combination of location-based verification and dynamic session key generation.
4Reliability
If location-based authentication is implemented, then security against unauthorized access is improved, but device complexity and measurement precision requirements increase
Solution Approach 1:
The patent changes the authentication parameter from traditional fixed credentials to dynamic location-based verification. Instead of verifying static passwords or tokens, the system uses the mobile device's current location coordinates and timing information as authentication parameters. The session key is generated based on these changing parameters, creating a location-time-bound authentication mechanism that prevents unauthorized access while using readily available location data without requiring excessive measurement precision.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Method and system for authenticating and controlling access to customer data is disclosed. Initially, a mobile agent raises a login request and a customer raises an authentication request through a pre-installed mobile application available on agent device and customer device. The unique identification details of customer device and agent device are stored on the system. The system performs a location match between the customer device and agent device thereafter a session key is generated. The session key is sent in parts to the customer device and mobile devices wherein at the time of authentication of agent device, the system performs a location match, session key match and identification detail match.