Mobile Device Computer Authenticator with Biometric Push Approval

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

High security computer applications require robust authentication methods to ensure only authorized users can access sensitive data and perform transactions, but existing solutions lack a convenient and secure way to verify user presence and identity.

Innovation Solution

A method utilizing a mobile device as a computer authenticator, involving a pre-registration process where a mobile token is activated and linked to a secure backend server, using biometric validation and PIN entry to ensure secure access, and an in-use process where the mobile device authenticates users by requesting biometric input for sign-in confirmation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (passwords, knowledge elements) are used, then ease of operation is improved, but security is worsened because they can be stolen, guessed, or forgotten

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines multiple authentication factors (biometric data, device presence, push notification approval) into a unified authentication system. The mobile device integrates the biometric sensor, push notification receiver, and authentication token into a single device that must be physically present and actively approved by the user to authenticate the computing device.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a push notification as an intermediary authentication step between the computing device and the authentication server. The push notification serves as a mediator that requires explicit user approval, adding a layer of security that prevents unauthorized authentication even if other credentials are compromised.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple authentication factors (biometric, device presence, push notification) are required, then security is improved, but device complexity is worsened

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The mobile device is designed to perform multiple authentication functions simultaneously: it stores biometric templates, generates and receives push notifications, validates authentication tokens, and communicates with both the authentication server and the computing device. This multi-functionality consolidates what would otherwise require multiple separate components into a single universal device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The mobile device autonomously performs biometric verification, push notification handling, and authentication token validation without requiring external intervention. The device uses its own built-in sensors and processing capabilities to complete authentication steps that would otherwise require separate devices or systems.

Inventive Principle:
Principle #25Self-service

3Reliability

If push notification approval is required for authentication, then security against unauthorized access is improved, but loss of time is worsened due to additional authentication steps

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The push notification is sent and displayed to the user before the authentication is completed, allowing the user to review and approve or deny the authentication request in advance. This preliminary action gives the user control over the authentication process and prevents unauthorized access while maintaining a relatively quick authentication flow.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication process allows the user to quickly approve or deny the push notification with a single tap, enabling rapid authentication when authorized. The system is designed to minimize the time required for user interaction while maintaining security, allowing legitimate users to authenticate quickly while still blocking unauthorized attempts.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS11544369B2Mobile device as a computer authenticator
Publication Date: 2023.01.03 BANK OF AMERICA CORP
  • US11544369B2 patent drawing
  • US11544369B2 patent drawing
  • US11544369B2 patent drawing

AI summary

A system for utilizing a mobile device as a computer authenticator is provided. The system may include a computing application executing on a computing apparatus. The system may include a secure backend server. The secure backend server may include a list of user identifiers, token serial numbers, device registration numbers and computing device identifiers. A pre-registration process may be used to embed a mobile token on a mobile device. A registration process may be used to pair the mobile device to the computing device. An in-use process may be used to authenticate the computing application using the mobile device.