Mobile Device as Security Token for Passwordless Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges in managing multiple online accounts with different user IDs and passwords, leading to security threats due to password reuse and theft, and existing identity-provider solutions do not provide sufficient protection against fraudulent access.

Innovation Solution

A computer-implemented method and system for mobile authentication, where a personal-mobile device acts as a security token, receiving user verification information, and communicating with a personal-identity server to authenticate the user, thereby allowing secure login to online accounts without exposing passwords on login webpages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users enter user ID and password on login webpage, then authentication is performed, but security is compromised due to password theft and fraudulent access

Engineering Contradiction:
Improveauthentication securityVSAvoidpassword theft and fraudulent access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the password from the login process by implementing single-sign-on functionality. The user's credentials are stored and managed by an identity provider service, and the user's computer device only needs to provide a user ID. The actual authentication is performed by the identity provider, which then provides authentication information to the service provider's server, eliminating the need for the user to enter their password on the service provider's login webpage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an identity provider service as an intermediary between the user and the service provider. The identity provider receives the user's login request, performs authentication using stored credentials, and then provides authentication information to the service provider's server. This intermediary approach allows the user to authenticate once with the identity provider and then access multiple services without repeatedly entering credentials, thereby improving security while maintaining ease of access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If users re-use passwords or choose simple passwords to manage multiple accounts, then ease of operation is improved, but security is threatened

Engineering Contradiction:
Improvepassword managementVSAvoidaccount security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a universal authentication system through single-sign-on functionality. The user establishes credentials with an identity provider once, and these credentials can be used to access multiple different services and accounts. The identity provider serves multiple functions: storing credentials, performing authentication, and providing authentication information to various service providers. This universal approach eliminates the need for users to manage multiple passwords across different services.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The identity provider performs self-service authentication by automatically verifying user credentials and providing authentication information to service providers without requiring manual password entry for each service. The system autonomously manages the authentication process, reducing user burden while maintaining security through centralized credential management.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10375062B2Computer-implemented method for mobile authentication and corresponding computer system
Publication Date: 2019.08.06 SAP SE
  • US10375062B2 patent drawing
  • US10375062B2 patent drawing
  • US10375062B2 patent drawing

AI summary

In one embodiment of the present invention a computerized method includes receiving at a personal-mobile device a first communication, which includes information for requesting user verification for logging into an account of a user, via a computing device. The account is with a service provided by an application server. The method includes starting a personal-authentication application on the personal-mobile device in response to receiving the first communication, and receiving in the personal-authentication application a user verification for confirming logging into the account. The method includes logging into the account via the computing device based on receipt of the user verification. Embodiments of the present invention provide enhanced security for logging into an account that a user may have with a service by providing that a personal-mobile device, such as a mobile telephone, which is personal to a user, is configured as a security token for login to the account.