Mobile Device QR Code Authentication via Untrusted Public Computers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices often face limitations in Internet connectivity, leading to frustration when users need to perform tasks that require internet access, especially in areas with no network coverage or limited data plans, and using public computing devices poses security risks.

Innovation Solution

A mobile device encrypts information and generates a QR code containing a payload with user identification and request details, which is then scanned by an untrusted computing device to send to a server via its internet connection, ensuring secure communication and avoiding security risks associated with public devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If a user uses a public computing device to access the Internet, then Internet connectivity is improved, but security risks increase

Engineering Contradiction:
ImproveInternet connectivityVSAvoidsecurity risks
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The system segments the authentication process into two parts: (1) The mobile device generates and stores encrypted credentials locally, and (2) The public computer only receives and transmits these encrypted credentials without being able to decrypt or access the actual user information. This segmentation allows the public computer to provide Internet connectivity while preventing it from accessing sensitive user data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary encryption layer between the user credentials and the public computer. The mobile device acts as an intermediary that holds the decryption keys, while the public computer serves as a temporary mediator that only handles encrypted data transmission. This intermediary mechanism enables Internet access through public computers while maintaining security by ensuring the public computer cannot access the actual credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a mobile device stores encrypted credentials locally, then security is improved, but the ability to use public computers for Internet access is limited

Engineering Contradiction:
ImprovesecurityVSAvoidability to use public computers
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The encryption system acts as an intermediary that enables the mobile device to securely interact with public computers. By encrypting credentials on the mobile device and having the public computer merely transmit these encrypted credentials to the server, the system maintains security while enabling adaptability to use public computing resources for Internet access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates an encrypted copy of the credentials that can be safely transmitted to and used by public computers. The mobile device generates encrypted credential data that is a functional copy for authentication purposes, but which cannot be reversed to obtain the original plaintext credentials. This copying mechanism allows public computer usage while maintaining security.

Inventive Principle:
Principle #26Copying

3Loss of energy

If Internet access is restricted due to network coverage or data limits, then cost control is improved, but user productivity decreases

Engineering Contradiction:
Improvedata usage controlVSAvoiduser productivity
Core Design Contradiction:
Loss of energyVSProductivity

Solution Approach 1:

The system performs preliminary actions by pre-generating and storing encrypted credentials on the mobile device before Internet access is needed. When the user needs to access the Internet through a public computer, the pre-prepared encrypted credentials can be quickly transmitted and used for authentication, enabling productive tasks without requiring extensive data usage or network setup time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240349048A1User authentication
Publication Date: 2024.10.17 CAPITAL ONE SERVICES LLC
  • US20240349048A1 patent drawing
  • US20240349048A1 patent drawing
  • US20240349048A1 patent drawing

AI summary

Methods and systems are disclosed herein for secure communication between computing devices. A mobile device may communicate with an untrusted device to cause the untrusted device to send information (e.g., encrypted information that the untrusted device is unable to decrypt) to a server using an Internet connection of the untrusted device. The mobile device may have limited or no access to the Internet. To prevent potential security risks associated with using a public or untrusted device, the mobile device may encrypt information stored on the mobile device (e.g., stored in a mobile application associated with the server), send it to the untrusted device (e.g., by displaying a QR code to a camera of the untrusted device), and the untrusted device may send the information to the server via a network connection of the untrusted device.