Mobile Terminal Authentication via Cloud-Relocated Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current device and service authentication methods are insecure, particularly in mobile terminals, as they often rely on password leakage, limited user registration, and cumbersome ID and password input, which compromises security and privacy, especially with the increasing use of multiple devices and cloud services.

Innovation Solution

A mobile terminal equipped with a short-range communicator and storage that sends authentication information to registered devices and cloud servers, using methods like ultrasonic-wave, Wi-Fi, or NFC, to facilitate secure device and service authentication, and manage biometric information for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If auto login is applied to service authentication by storing ID and password locally, then convenience is improved, but security is worsened due to password leakage risk

Engineering Contradiction:
ImproveconvenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the authentication information storage function from the device itself and relocates it to a cloud server. The device no longer stores ID and password locally, but instead retrieves authentication information from the cloud when needed, eliminating the security risk of local storage while maintaining automatic login functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The cloud server acts as an intermediary between the device and the authentication system. Instead of the device directly storing and using authentication credentials, the cloud server mediates by providing authentication information to the device upon request, thereby securing credentials remotely.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple users are registered to tablet PC, then versatility is improved, but privacy protection is worsened among users

Engineering Contradiction:
Improvemulti-user supportVSAvoidprivacy leakage
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments authentication information by user and stores it separately in the cloud server for each user. When a user accesses the device, the system retrieves only that specific user's authentication information from the cloud, preventing other users from accessing their personal data and thereby protecting privacy while maintaining multi-user support.

Inventive Principle:
Principle #1Segmentation

3Reliability

If device authentication uses password or pattern input, then security is improved, but ease of operation is worsened due to manual input requirement

Engineering Contradiction:
ImprovesecurityVSAvoidconvenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication by automatically retrieving stored authentication information from the cloud server when the device is unlocked or accessed. This eliminates the need for manual password or pattern input at the time of use, as the authentication credentials are pre-fetched and ready for immediate use.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9980131B2Mobile terminal, device and control method thereof
Publication Date: 2018.05.22 SAMSUNG ELECTRONICS CO LTD
  • US9980131B2 patent drawing
  • US9980131B2 patent drawing
  • US9980131B2 patent drawing

AI summary

A device includes: a short-range communicator which is configured to communicate with at least one mobile terminal by a short-range communication method; and a controller which is configured to determine whether a mobile terminal targeted for approaching is a registered mobile terminal if it is detected that the mobile terminal approaches the device, and controls the short-range communicator to receive the first authentication information corresponding to the device from the approached mobile terminal if the approached mobile terminal is determined as the registered mobile terminal, and authenticate a user of the device through the received first authentication information. With this, a user can be authenticated by a simple method of making the mobile terminal approach the device without inputting his/her authentication information, thereby improving user's convenience and strengthening security effect.