Mobile Authorization System with Dynamic Credential Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authorization systems are inefficient in utilizing mobile devices for secure access to services, as they often require manual entry of credentials and lack seamless integration with mobile technology, especially in scenarios where multiple approvals are needed.

Innovation Solution

A method and system that utilizes mobile devices to receive authorization requests, process user inputs, and send responses to a server for service access, incorporating a processor, memory, and an authorization module to manage approval lists and determine authorization levels, enabling secure and efficient access to services through wireless communication networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual credential entry is required for authorization, then security can be maintained through verified credentials, but the ease of operation deteriorates due to manual input requirements

Engineering Contradiction:
Improveauthorization securityVSAvoidmanual credential entry
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mobile device automatically performs authorization by selecting credentials from stored sets and sending authorization requests without requiring manual credential entry by the user. The system serves itself by autonomously managing the authorization process while maintaining security through pre-configured credential sets.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Credential sets are pre-configured and stored in the mobile device before authorization is needed. The user previously set up multiple credential sets with different authorization levels, so when authorization is required, the system can immediately use the appropriate pre-prepared credentials without manual input.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If multiple authorization levels are implemented for different services, then authorization precision is improved, but the device complexity increases due to managing multiple credential sets

Engineering Contradiction:
Improveauthorization level differentiationVSAvoidcredential set management
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

Instead of managing complex unique credentials for each service, the system creates simplified copies or representations of credential sets in the mobile device. Each credential set is stored as a discrete unit that can be selectively applied, reducing the perceived complexity while maintaining the ability to differentiate authorization levels across multiple services.

Inventive Principle:
Principle #26Copying

3Productivity

If automated authorization using mobile devices is implemented, then productivity is improved through faster access, but the reliability may worsen due to potential security vulnerabilities in automated systems

Engineering Contradiction:
Improveauthorization speedVSAvoidautomated security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system dynamically selects which credential set to use based on the current service and authorization requirements rather than using static, fixed credentials. The mobile device adapts its authorization approach in real-time, choosing the appropriate pre-configured credential set based on the service context, which maintains security while enabling fast automated authorization.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8566911B2Method of obtaining authorization for accessing a service
Publication Date: 2013.10.22 MALIKIE INNOVATIONS LTD
  • US8566911B2 patent drawing
  • US8566911B2 patent drawing
  • US8566911B2 patent drawing

AI summary

Methods and devices for obtaining authorization for a requestor to access a service are provided. In accordance with one embodiment, there is provided a method comprising receiving a requestor request for access to a service; sending an authorization request to one or more mobile devices associated with one or more authorizers on a first approval list; receiving an authorization response from the one or more mobile devices associated with the one or more authorizers on the first approval list; determining whether a predetermined level of authorization is received; and when the predetermined level of authorization is received, authorizing access to the service.