Mobile Device Desktop Authentication via Cloud Clearinghouse
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current digital authentication methods, such as proximity-based authentication using mobile devices, are vulnerable to unauthorized access if the mobile device is stolen or compromised, and they require high maintenance for federated identity management.
Innovation Solution
A cloud-based clearinghouse system that integrates mobile device authentication using biometrics, social data, and other methods to enable secure login to desktops and laptops both when connected and disconnected from the internet, using USB, Bluetooth, or local Wi-Fi connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If proximity-based authentication using mobile devices is used, then ease of operation is improved, but security is worsened because thieves can gain unauthorized access by bringing stolen mobile devices close to computing devices
Solution Approach 1:
The authentication system is segmented into multiple independent verification factors: device proximity detection, biometric verification, and device ownership validation. Each factor operates independently and must all be satisfied for successful authentication, preventing single-point failure modes
Solution Approach 2:
The system performs preliminary verification of device ownership and user identity before allowing proximity-based authentication to take effect. Biometric data is pre-verified and device credentials are pre-authenticated, ensuring that even if a stolen device is brought close to the computer, unauthorized access is blocked without proper biometric verification
2Adaptability or versatility
If federated identity management is implemented, then adaptability is improved, but device complexity is worsened due to high maintenance requirements
Solution Approach 1:
The authentication system implements a universal protocol that works across multiple organizations and networks without requiring separate federated identity management configurations for each partner. The mobile device serves multiple functions: it acts as both the authentication credential holder and the communication bridge between different networks, eliminating the need for complex bilateral federation setups
Solution Approach 2:
The mobile device functions as an intermediary that mediates authentication between different networks and organizations. Instead of requiring direct federation between Company A and Company B systems, the mobile device translates and validates credentials across network boundaries, significantly reducing the maintenance burden on organizational systems
Data Source
AI summary
A technique is provided that integrates authentication from a mobile device (e.g., using biometrics, social informational data, questions and answers, and more) to allow login to laptops and desktops while they are disconnected from the Internet using a USB cable connection, Bluetooth or local wifi or any other similar protocol and/or connected to Internet without USB. The technique provides a cloud clearinghouse that ties a person's or entity's mobile device(s) to an identity that's used to authenticate a person (could be the same person) on a laptop, desktop, or similar computer system.


