Mobile Device Digital Fingerprint Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user authentication systems, particularly in online transactions, face vulnerabilities such as weak protection with one-factor authentication and high costs associated with two-factor authentication methods, which can be circumvented by techniques like SIM-card cloning and key-logging, and require users to manually enter codes, leading to potential delays and security threats.
Innovation Solution
A method and system that utilizes a mobile communications device to generate a unique digital identifier based on its IMEI and SIM card number, combined with a random number, stored securely on the device, which is used to establish a secure communication link with an authentication server to confirm or deny transactions, eliminating the need for manual code entry and enhancing security by requiring real-time user interaction.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If one-factor authentication (username and password) is used, then ease of operation is improved, but security is worsened
Solution Approach 1:
The patent introduces a mobile device as an intermediary between the user and the authentication system. The mobile device generates and transmits a digital identifier (fingerprint) that serves as a mediator to verify user identity without requiring the user to manually enter complex credentials, thus maintaining ease of operation while significantly improving security through device-specific authentication
Solution Approach 2:
The system creates a digital copy (fingerprint) of the mobile device's unique characteristics including IMEI, SIM card number, and other hardware identifiers. This digital fingerprint serves as a secure replica of the device's identity that can be transmitted and verified without exposing sensitive information, enabling secure authentication while maintaining operational simplicity
2Reliability
If two-factor authentication using SMS OTP is used, then security is improved, but cost is worsened
Solution Approach 1:
The mobile device autonomously generates and transmits its own digital identifier (fingerprint) without requiring the authentication server to initiate SMS messages or perform complex verification procedures. The device self-services the authentication process by providing its unique identifiers, eliminating the need for costly SMS OTP generation and transmission while maintaining strong security
Solution Approach 2:
The patent extracts the essential identifying information (IMEI, SIM card number, hardware identifiers) directly from the mobile device and uses these extracted elements to create a fingerprint. This extraction approach eliminates the need for expensive SMS-based authentication mechanisms while retaining the security benefits of two-factor authentication through device-specific identification
3Reliability
If offline OTP generating hardware is used, then security is improved, but device complexity is worsened
Solution Approach 1:
The patent makes the mobile device universal by utilizing its existing multi-functional capabilities (telephony, identification, communication) for authentication purposes. The mobile device's existing hardware components (IMEI, SIM card, processor) are repurposed to generate security credentials, eliminating the need for separate dedicated OTP hardware while maintaining security
Solution Approach 2:
The system merges the authentication function with the mobile device's existing identification and communication functions. By combining the device's unique identifiers (IMEI, SIM number) with its processing capabilities, the patent creates an integrated authentication solution that eliminates separate hardware requirements while providing robust security through device-specific fingerprints
4Reliability
If manual code entry is required, then security is improved, but productivity is worsened
Solution Approach 1:
The patent replaces the mechanical process of manual code entry and transcription with an automated electronic transmission system. The mobile device automatically generates and transmits its digital identifier through electronic communication channels, eliminating the manual typing and transcription process while maintaining security through the uniqueness of the device fingerprint
Solution Approach 2:
The mobile device's digital identifier (fingerprint) is pre-configured and ready for transmission before the authentication process begins. This preliminary preparation eliminates the need for real-time manual code generation and entry during the transaction, allowing for rapid automated authentication that maintains security while significantly improving transaction speed
Data Source
AI summary
A method and system for authenticating secure transactions between a transacting user and a secure transaction host is provided. The system includes a mobile phone software application installed on a transacting user's mobile phone which is configured to compose a digital fingerprint uniquely associated with the specific mobile phone on which it is installed. The system further includes an authentication service provider with which users of the system may be enrolled by registering at least the digital identifiers composed by the applications installed on their mobile communication devices in an authentication database. The authentication service provider is configured to authenticate secure transactions on request from secure transaction hosts by sending transaction confirmation requests to mobile phones of enrolled users requiring them to confirm or deny secure transactions before such transactions are allowed to be finalized.


