Mobile Authentication via Caller ID and Logon Key

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for authenticating transactions via mobile telephones are cumbersome and time-consuming due to the limitations of mobile keyboards, requiring users to remember multiple usernames and passwords, which often leads to security compromises or non-use of services.

Innovation Solution

A method that utilizes caller identification information to authenticate users by sending a logon key via a message, allowing users to efficiently access secure web or WAP sites with minimal keystrokes, potentially using a hyperlink and incorporating additional security measures like PIN codes or biometrics for sensitive operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (usernames and passwords) are used, then security can be maintained, but the authentication process becomes cumbersome and time-consuming due to mobile keyboard limitations

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the authentication verification process from the mobile device keyboard input and transfers it to the network server. The server receives the device identifier, verifies credentials, and sends back authentication data, eliminating the need for users to manually input complex passwords on mobile keyboards while maintaining security

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary authentication server that mediates between the mobile device and the target system. The server handles the complex verification process using device identifiers and stored credentials, acting as a bridge that simplifies user interaction while maintaining authentication security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple usernames and passwords are required for different services, then security coverage is improved, but user memory burden increases and security compromises occur

Engineering Contradiction:
Improvesecurity coverageVSAvoidpassword memory retention
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent creates a universal authentication system where a single device identifier can be used across multiple services and systems. The authentication server stores and manages credentials for different services, allowing the same mobile device to authenticate to multiple targets without requiring users to remember separate passwords for each service

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If secure storage locations are used for passwords, then security is maintained, but accessibility in mobile settings is reduced

Engineering Contradiction:
Improvepassword securityVSAvoidpassword accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical system of physical password storage (write-downs, secure locations) with an electronic authentication system. The server stores credentials electronically and retrieves them based on device identifiers, eliminating the need for physical storage while maintaining security and improving accessibility through network-based retrieval

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8325889B2Efficient authentication of a user for conduct of a transaction initiated via mobile telephone
Publication Date: 2012.12.04 MOBILEAXEPT NORTH AMERICA INC
  • US8325889B2 patent drawing
  • US8325889B2 patent drawing
  • US8325889B2 patent drawing

AI summary

A method and system for authenticating a user for conduct of a transaction initiated by the user via a data-enabled telephone is presented. Efficient use is made of keystrokes on the data-enabled telephone. The data-enabled telephone is capable of initiating telephone calls over a telephone network and of engaging in two-way data communication with a data server in a network and the server enables conduct of the transaction. Caller identification information is received at the server. The information is associated with a telephone call request initiated by the user via the data-enabled telephone to a service number. The caller identification provides basis for authentication of the user and the caller identification information received at the service number is used to address a message to the user. Included in such a message is a logon key for use by the user in accomplishing the transaction. Thus the user can use the logon key to enter into data communication with the server for conduct of the transaction.