Mobile Device Binding for Seamless Cross-App Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face inconvenience in electronic commerce due to the need for repetitive login processes when switching between apps or websites, which hampers the efficiency of financial transactions and user experience.

Innovation Solution

Implementing a secure device binding method that allows a mobile device to be linked to a user account, enabling streamlined authentication and bypassing the need for repeated login credentials across apps and websites that share a service provider library, while maintaining secure connections through unique device identifiers and risk management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users log in to each app or website separately, then security is maintained through individual authentication, but user convenience deteriorates due to repetitive login processes

Engineering Contradiction:
Improveuser convenienceVSAvoidtime for repetitive login
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent combines multiple authentication sessions into a single device-level binding. When a user logs in once to a service provider, the authentication credentials are bound to the mobile device, allowing the user to access multiple apps and websites without re-entering credentials. This merging of authentication states across different applications resolves the technical contradiction by eliminating repetitive login processes while maintaining security through the bound device connection.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements preliminary device binding during the initial login process. The mobile device is bound to the user account before the user needs to access subsequent apps or websites. This preliminary action of binding the device stores authentication information in advance, allowing future access without repeated login. The binding process prepares the authentication state beforehand, resolving the contradiction by eliminating future repetitive login requirements.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If device binding is implemented across all apps, then user convenience improves through seamless transitions, but security may deteriorate due to potential unauthorized access

Engineering Contradiction:
Improvetransaction efficiencyVSAvoidtransaction security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies local quality by implementing device binding at the service provider level rather than universally across all applications. Each service provider can independently choose to implement device binding for their apps and websites that use their library. This localized implementation allows participating service providers to enhance transaction efficiency through seamless transitions while maintaining their own security protocols, resolving the contradiction by allowing productivity improvement without compromising overall system security.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent incorporates feedback mechanisms where the service provider's library monitors and manages the device binding status. The system tracks which devices are bound to which accounts and can enforce security policies based on this information. This feedback loop allows the system to maintain security by verifying bound device status before allowing transactions, while still enabling convenient seamless transitions for authenticated devices, thus resolving the contradiction between productivity and reliability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10152705B2Quick payment using mobile device binding
Publication Date: 2018.12.11 PAYPAL INC
  • US10152705B2 patent drawing
  • US10152705B2 patent drawing
  • US10152705B2 patent drawing

AI summary

Methods and systems are provided for secure device binding that provides user convenience through avoiding repetitive logging in when changing apps or moving from website to website. A mobile device undergoes binding to an account so that customers do not always have to enter their password when going through a financial transaction process, on a known (e.g., registered) mobile device. A device may be bound during an initial login, and once logged in, the user can select an option to be “remembered” so that the user need not re-login on the same device for future visits with an app or to a website that shares the service provider library.