Mobile Device Temporary Password Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN authentication schemes require users to carry dedicated hardware tokens for each network, which is inconvenient and limits universality, especially when accessing multiple networks or sharing devices, and requires cumbersome software updates across multiple devices.

Innovation Solution

A method using a mobile telecommunication device to request and receive a temporary password from a service provider, eliminating the need for network-specific hardware tokens by integrating authentication functionality into the mobile device, allowing access to multiple networks with a single device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated hardware tokens are used for each network, then authentication security is improved, but device complexity and portability are worsened

Engineering Contradiction:
Improveauthentication securityVSAvoidnumber of hardware tokens
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the functionality of multiple network-specific hardware tokens into a single mobile communication device. The mobile device stores multiple authentication credentials and can selectively present the appropriate credential to different networks, eliminating the need to carry separate physical tokens for each network while maintaining authentication security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The mobile communication device is designed to perform multiple authentication functions across different networks. It can store and manage credentials for multiple networks simultaneously, providing universal access capability that replaces the need for network-specific hardware tokens while maintaining security through selective credential presentation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple hardware tokens are carried for different networks, then access to multiple networks is enabled, but ease of operation is worsened

Engineering Contradiction:
Improveaccess to multiple networksVSAvoidconvenience of carrying and using tokens
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

Multiple network access credentials are merged into a single mobile device, allowing users to access multiple networks without carrying multiple separate hardware tokens. The device automatically manages which credential to present based on the target network, simplifying the user experience while maintaining multi-network access capability.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If VPN client software is installed on multiple mobile computers, then network access flexibility is improved, but ease of repair and updates are worsened

Engineering Contradiction:
Improvenetwork access flexibilityVSAvoidsoftware update complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of repair

Solution Approach 1:

The authentication functionality is extracted from the VPN client software on mobile computers and centralized in the mobile communication device. The mobile device stores authentication credentials and manages the authentication process, eliminating the need to install and maintain VPN client software on multiple mobile computers. This centralization simplifies software updates and maintenance while preserving network access flexibility.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7590847B2Mobile authentication for network access
Publication Date: 2009.09.15 ALCATEL LUCENT SA
  • US7590847B2 patent drawing
  • US7590847B2 patent drawing
  • US7590847B2 patent drawing

AI summary

The present invention provides a method for authenticating a user to a network by means of a temporary and/or one-time password. The temporary and/or one-time password is provided by a service provider that can be accessed by means of a mobile telecommunication device. The temporary password is provided on demand, when the user invokes a corresponding access request that is transmitted to the service provider by means of the mobile telecommunication device. The service provider checks and asserts a received access request and generates the temporary password by making use of a dedicated cryptographic method. The generated temporary password is finally transmitted to the personal mobile device of the user that is adapted to transmit the received temporary password to a gateway of a network in order to authenticate the user to the network. Moreover, the mobile telecommunication device provides establishing of an IP-based connection between a user's computing device and the network. The mobile telecommunication device therefore provides establishing of at least two communication links to the network and to the user's computing device. In this way, an authentication procedure can be autonomously performed by means of the user's personal mobile telecommunication device. Installing and/or maintaining authentication related software on the user's computing device therefore becomes superfluous.