Mobile Device Authentication via Session Key and Location Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for accessing customer data are plagued by issues such as physical presence requirements, infrastructure costs, and vulnerabilities like password mismanagement and data leakage, necessitating a more secure and convenient solution.

Innovation Solution

A system and method utilizing a mobile device-based authentication system that generates a one-time session key, validated through geo-spatial location matching and unique identification, to control access to customer data, ensuring secure access without storing sensitive information on the device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric-based authentication is used, then authentication security is improved, but physical presence requirement and device complexity increase

Engineering Contradiction:
Improveauthentication securityVSAvoidphysical presence requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical authentication methods (physical presence, smart cards, biometrics) with a mobile device-based authentication system that uses software-based session keys and location verification. The mechanical/physical authentication requirements are substituted with digital credential verification through the mobile device, eliminating the need for physical presence while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates a copy of the authentication mechanism through the mobile device session key. Instead of requiring the actual customer to be physically present with their biometric data or smart card, the system generates a temporary session key that acts as a copy of the authentication credential. This session key can be verified remotely without requiring the physical customer, thus resolving the contradiction between security and physical presence requirement.

Inventive Principle:
Principle #26Copying

2Ease of operation

If password-based authentication is used, then ease of operation is improved, but security vulnerabilities and data leakage risk increase

Engineering Contradiction:
Improveauthentication convenienceVSAvoiddata leakage risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces dynamic session keys that are generated temporarily for each authentication session rather than using static passwords. The session key is created dynamically based on the customer's mobile device location and authentication request. This dynamic approach eliminates the security vulnerabilities of static passwords while maintaining ease of operation, as customers simply need to provide their mobile device for location-based verification.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a location verification intermediary between the authentication system and the customer. Instead of directly storing and verifying passwords (which creates data leakage risks), the system uses mobile device location data as an intermediary verification mechanism. The location information acts as a mediator that confirms the customer's identity without requiring the system to store sensitive password data, thus eliminating data leakage vulnerabilities while maintaining operational convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If static password and dynamic token authentication is used, then authentication security is improved, but infrastructure cost and operational inconvenience increase

Engineering Contradiction:
Improveauthentication securityVSAvoidinfrastructure cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables the customer's mobile device to serve as the authentication token itself. Instead of requiring separate hardware tokens that need to be managed, retrieved, and coded, the mobile device uses its existing location services and authentication capabilities to generate and verify session keys. The system leverages the mobile device's inherent features (GPS, processor, display) for authentication, eliminating the need for additional infrastructure hardware and reducing operational inconvenience.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent makes the mobile device universal for authentication purposes. The mobile device serves multiple functions: it acts as the authentication token, provides location verification, displays verification codes, and communicates with the authentication system. This multi-functionality eliminates the need for separate dedicated authentication hardware, reducing infrastructure costs while maintaining high security through the combination of location-based verification and dynamic session key generation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If location-based authentication is implemented, then security against unauthorized access is improved, but device complexity and measurement precision requirements increase

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidlocation verification accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent changes the authentication parameter from traditional fixed credentials to dynamic location-based verification. Instead of verifying static passwords or tokens, the system uses the mobile device's current location coordinates and timing information as authentication parameters. The session key is generated based on these changing parameters, creating a location-time-bound authentication mechanism that prevents unauthorized access while using readily available location data without requiring excessive measurement precision.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3122017B1Systems and methods of authenticating and controlling access over customer data
Publication Date: 2020.04.29 TATA CONSULTANCY SERVICES LTD
  • EP3122017B1 patent drawingFigure 1
  • EP3122017B1 patent drawingFigure 2
  • EP3122017B1 patent drawingFigure 3

AI summary

Method and system for authenticating and controlling access to customer data is disclosed. Initially, a mobile agent raises a login request and a customer raises an authentication request through a pre-installed mobile application available on agent device and customer device. The unique identification details of customer device and agent device are stored on the system. The system performs a location match between the customer device and agent device thereafter a session key is generated. The session key is sent in parts to the customer device and mobile devices wherein at the time of authentication of agent device, the system performs a location match, session key match and identification detail match.