Mobile Device Authentication for Secure Web Login

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for accessing secure web services via mobile devices do not adequately protect user privacy and are prone to operational errors, as users must manually enter identification data.

Innovation Solution

The method involves the web service and authentication service identifying the user, with the authentication process occurring between the user's mobile device and an authentication service, eliminating the need for user-specific data entry and reducing errors by using a mobile device-based authentication application that initiates a secure authentication process through an authentication service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the user manually enters identification data to authenticate on the PC browser, then the authentication process can be completed, but user privacy is compromised and operational errors occur

Engineering Contradiction:
Improveauthentication accuracyVSAvoiduser data entry burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mobile device automatically performs authentication without requiring the user to manually enter identification data. The authentication application on the mobile device self-serviceedly generates and transmits authentication credentials to the PC browser, eliminating the need for user data entry while ensuring accurate authentication.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The mobile device acts as an intermediary between the user and the authentication system. Instead of the user directly entering data on the PC, the mobile device receives authentication requests, processes them locally, and automatically transmits the necessary credentials back to the PC browser, thereby protecting user privacy and eliminating manual data entry errors.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the user discloses identity to the web service for authentication, then access to the secure web service is granted, but user privacy protection is weakened

Engineering Contradiction:
Improveweb service access capabilityVSAvoiduser privacy
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The mobile device serves as an intermediary that enables web service access without requiring the user to disclose personal identification information to the web service. The authentication credentials are generated and transmitted automatically by the mobile device's authentication application, allowing the user to access secure web services while maintaining privacy protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of using the user's actual identification data, the system uses a copied or surrogate authentication credential generated by the mobile device's authentication application. This credential copy enables authentication and web service access without exposing the user's real personal information to the web service.

Inventive Principle:
Principle #26Copying

3Ease of operation

If automated authentication is implemented between mobile device and authentication service, then operational errors are eliminated and privacy is protected, but system complexity increases

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidauthentication system structure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The mobile device's authentication application provides multiple functions within a single integrated solution: it stores authentication credentials, generates authentication requests, transmits credentials to the PC browser, and verifies authentication status. This multi-functionality reduces the need for separate components while achieving automated, error-free authentication.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication application on the mobile device combines multiple authentication-related functions into a single integrated component. It merges credential storage, request generation, data transmission, and verification capabilities into one unified application, thereby simplifying the overall system structure while maintaining automated authentication functionality.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2456157B1Protecting privacy when a user logs into a secure web service using a mobile device
Publication Date: 2013.06.05 DEUTSCHE TELEKOM AG
  • EP2456157B1 patent drawingFigure 1
  • EP2456157B1 patent drawingFigure 2

AI summary

The method involves producing a communication connection between a browser (51) of a communication device (50) and an authentication service (34). An address of an authentication device is transmitted to a mobile device (60), and safe authentication is executed between the authentication service and the mobile device. A password is produced by the authentication service when the authentication is succeeded. The password is transmitted to the browser, and a user is logged-on to protected web service (41) when the password is transmitted from the browser to the protected web service. An independent claim is also included for a telecommunication system protecting privacy during logging-on of user to protected wed service by a mobile device.