Mobile Device Authentication via Companion Proximity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices, such as smartphones and smart watches, face challenges in securely authenticating transactions without compromising security when stolen or lost, as they store sensitive information and are used for various secure functions, necessitating a method to restrict access and ensure secure transactions.

Innovation Solution

A system where a master device authenticates a transaction-enabled device, which can delegate authority to a companion device, ensuring secure transactions only occur when the companion device is in communication, using unique authentication information and restrictions, such as proximity requirements, to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a mobile device stores sensitive information and enables secure transaction functions, then the device provides convenient access to confidential data and payment capabilities, but the device becomes vulnerable to unauthorized access if stolen or lost

Engineering Contradiction:
Improveconvenience of accessing secure functionsVSAvoidvulnerability to unauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a companion device as an intermediary that must be present and communicate with the transaction-enabled device to authorize secure transactions. This mediator layer ensures that even if the transaction-enabled device is stolen, unauthorized users cannot access secure functions without the companion device's authentication, thus resolving the contradiction between convenience and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a user carries a smartphone for secure transactions, then the user has full access to payment and confidential information, but the user cannot achieve the convenience of wearable technology without compromising security

Engineering Contradiction:
Improveconvenience of wearable technologyVSAvoidsecurity of secure functions
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication system into two separate devices: a transaction-enabled device (wearable) and a companion device (smartphone). The wearable device provides convenience for transactions, while the companion device provides security oversight. This segmentation allows the system to achieve both the convenience of wearable technology and the reliability of smartphone-based security measures.

Inventive Principle:
Principle #1Segmentation

3Productivity

If a transaction-enabled device allows access to secure functions without verification, then the device provides fast and easy transactions, but the device risks unauthorized use when lost or stolen

Engineering Contradiction:
Improvespeed of transaction processingVSAvoidsecurity against unauthorized use
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary authentication by requiring the transaction-enabled device to verify communication with the companion device before enabling secure transaction functions. This pre-verification step ensures that only authorized devices can access secure functions, preventing unauthorized use while maintaining fast transaction processing once authenticated.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If a device implements strict authentication requirements for secure transactions, then the device maintains high security, but the device reduces convenience and increases complexity of use

Engineering Contradiction:
Improvesecurity of authenticationVSAvoidcomplexity of authentication process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service authentication where the companion device automatically verifies its presence and communication status with the transaction-enabled device without requiring manual user intervention. The system autonomously manages the authentication process, maintaining high security while minimizing the complexity and burden on the user.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11132694B2Authentication of mobile device for secure transaction
Publication Date: 2021.09.28 PAYPAL INC
  • US11132694B2 patent drawing
  • US11132694B2 patent drawing
  • US11132694B2 patent drawing

AI summary

There are provided systems and methods for authenticating a mobile device for use in a secure transaction. A user having a master device authenticated for use in a secure transaction system, such as an electronic payment system, identifies a secondary device to be enabled for use in processing a secure transaction. The secondary device connects to a companion device and shares information associated with the secondary device and companion device with a transaction processing server, which returns authentication information associated with both devices. When the user initiates a secure transaction, the secondary device identifies whether the third device is in proximity. The secure transaction is processed only if the second and third devices are in communication and authenticated during the transaction. If the secondary device is lost or stolen, the device may be disabled until reauthenticated through the master device.