Mobile Device Binding for Seamless Cross-App Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face inconvenience in electronic commerce due to the need for repetitive login processes when switching between apps or websites, which hampers the efficiency of financial transactions and user experience.
Innovation Solution
Implementing a secure device binding method that allows a mobile device to be linked to a user account, enabling streamlined authentication and bypassing the need for repeated login credentials across apps and websites that share a service provider library, while maintaining secure connections through unique device identifiers and risk management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users log in to each app or website separately, then security is maintained through individual authentication, but user convenience deteriorates due to repetitive login processes
Solution Approach 1:
The patent combines multiple authentication sessions into a single device-level binding. When a user logs in once to a service provider, the authentication credentials are bound to the mobile device, allowing the user to access multiple apps and websites without re-entering credentials. This merging of authentication states across different applications resolves the technical contradiction by eliminating repetitive login processes while maintaining security through the bound device connection.
Solution Approach 2:
The patent implements preliminary device binding during the initial login process. The mobile device is bound to the user account before the user needs to access subsequent apps or websites. This preliminary action of binding the device stores authentication information in advance, allowing future access without repeated login. The binding process prepares the authentication state beforehand, resolving the contradiction by eliminating future repetitive login requirements.
2Productivity
If device binding is implemented across all apps, then user convenience improves through seamless transitions, but security may deteriorate due to potential unauthorized access
Solution Approach 1:
The patent applies local quality by implementing device binding at the service provider level rather than universally across all applications. Each service provider can independently choose to implement device binding for their apps and websites that use their library. This localized implementation allows participating service providers to enhance transaction efficiency through seamless transitions while maintaining their own security protocols, resolving the contradiction by allowing productivity improvement without compromising overall system security.
Solution Approach 2:
The patent incorporates feedback mechanisms where the service provider's library monitors and manages the device binding status. The system tracks which devices are bound to which accounts and can enforce security policies based on this information. This feedback loop allows the system to maintain security by verifying bound device status before allowing transactions, while still enabling convenient seamless transitions for authenticated devices, thus resolving the contradiction between productivity and reliability.
Data Source
AI summary
Methods and systems are provided for secure device binding that provides user convenience through avoiding repetitive logging in when changing apps or moving from website to website. A mobile device undergoes binding to an account so that customers do not always have to enter their password when going through a financial transaction process, on a known (e.g., registered) mobile device. A device may be bound during an initial login, and once logged in, the user can select an option to be “remembered” so that the user need not re-login on the same device for future visits with an app or to a website that shares the service provider library.


