Mobile Identity Authentication with Session Keys and Action Confirmation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile devices face challenges in providing high-security identity authentication for electronic devices with low costs and ease of implementation.

Innovation Solution

A method involving a mobile device and electronic device that exchange session keys to authenticate identity through wireless communication, using different antennas or power levels to ensure secure communication within a preset distance, and user confirmation of actions or codes to verify session integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used, then implementation cost is low, but security is insufficient

Engineering Contradiction:
Improveauthentication securityVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is divided into multiple independent steps: generating session key, encrypting action information, user confirmation, and final authentication. Each step can be independently implemented and verified, improving security without requiring complete system redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A session key is introduced as an intermediary element between the mobile device and electronic device. This session key enables secure communication without requiring the devices to share pre-established secrets, simplifying implementation while enhancing security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If complex authentication protocols are implemented, then security is improved, but user operation becomes complicated

Engineering Contradiction:
Improveauthentication securityVSAvoiduser operation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically generates session keys, performs encryption, and verifies authentication without requiring user intervention in these technical processes. The user only needs to confirm the displayed action information, making the complex security protocol transparent to the user.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses visual display of action information and authentication codes that the user can easily perceive and confirm. The authentication state is clearly indicated through display updates, making the process user-friendly despite the underlying complexity.

Inventive Principle:
Principle #32Color changes

3Reliability

If secure distance restrictions are enforced, then security is improved, but communication flexibility is reduced

Engineering Contradiction:
Improvesecret information securityVSAvoidcommunication flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adjusts the session key based on the distance between devices. When devices are within the secure distance, normal authentication proceeds. When distance exceeds the threshold, the system detects potential spoofing and adjusts authentication requirements accordingly, providing both security and flexibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication protocol changes parameters such as session key generation and verification requirements based on the measured distance between devices. This allows the system to maintain security for close-range communications while accommodating longer-distance scenarios with additional verification steps.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12375284B2Identity authentication method, electronic device, and computer-readable storage medium
Publication Date: 2025.07.29 HUAWEI TECH CO LTD
  • US12375284B2 patent drawing
  • US12375284B2 patent drawing
  • US12375284B2 patent drawing

AI summary

An identity authentication method and a mobile device. The mobile device performs receiving a first message of an electronic device within a second distance from the electronic device, where the first message includes a randomly generated session key, randomly generating first action information in response to the first message, and obtaining a second message by encrypting the first action information using the session key, sending the second message to the electronic device. displaying first confirmation information to determine whether the electronic device performs a first action indicated by the first action information, receiving first input used for confirmation, and prompting that identity authentication on the electronic device succeeds, where the second distance is less than or equal to a preset secure distance.