Mobile Device Authentication via Ticket ID Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user authentication systems face challenges in balancing security and usability, as increasing security often imposes additional burdens on users, and there is a need for a more secure method to authenticate users accessing restricted resources, especially in systems like e-banking and content subscription services.
Innovation Solution
A system that uses a mobile communication device to authenticate users by comparing sensory representations of a login session between a client computer system and the mobile device, leveraging a challenge-response exchange with cryptographic keys, to verify user identity and grant access to restricted resources without requiring frequent user input.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If one-time codes are transmitted via voice message or SMS to increase authentication security, then security is improved, but user burden increases and usability deteriorates
Solution Approach 1:
The patent introduces a hardware display token (keyfob) as an intermediary device that generates and displays one-time codes locally. This mediator eliminates the need for SMS or voice message transmission, reducing user burden while maintaining security through the physical possession requirement and local code generation capability.
Solution Approach 2:
The patent creates a physical copy of the authentication mechanism in the form of a hardware token that replicates the one-time code generation function. This copying approach allows the authentication system to operate independently of network communication for code delivery, improving usability while preserving security through the distributed authentication capability.
2Reliability
If hardware display tokens are used to provide one-time codes, then authentication security is improved, but device complexity increases
Solution Approach 1:
The patent extracts the one-time code generation function from the main authentication server and places it in a separate, dedicated hardware token device. This extraction simplifies the overall system architecture by creating independent, single-function components that are easier to manufacture, distribute, and manage, while maintaining security through the distributed authentication approach.
Data Source
AI summary
Described systems and methods allow secure and relatively convenient authentication of a secure login session. When a user initiates a login session on a secure site using a client computer system (e.g. laptop, tablet, smartphone), matching login session identifiers (Ticket IDs) are displayed on the client computer system and a mobile communication device uniquely associated with the user (e.g. the user's smartphone). Upon verifying that the two Ticket IDs match, the user accepts the Ticket ID displayed on the mobile communication device, which causes the login session by the client computer system to proceed. Identity verification proceeds largely in the background, through communications between an authentication server, service provider server, and mobile communication device, and involves minimal user input. Techniques are disclosed for reducing the incidence of inadvertent acceptance of incorrect Ticket IDs by users, and reducing system vulnerability to attacks.


