Mobile Wireless Authentication via Temporary Logon ID

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face security concerns when accessing public or shared computer terminals, as they risk exposing sensitive information like passwords to keyloggers, leading to frequent password changes and inconvenience, especially when accessing multiple accounts.

Innovation Solution

A communication system that includes a mobile wireless device with a wireless transceiver and sensor, capable of retrieving a temporary authenticated logon ID from a computer terminal and communicating it via NFC or optical patterns to securely authenticate logon to a server, eliminating the need for direct password input and reducing the risk of password compromise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users input passwords directly on public computer terminals, then authentication can be performed, but security is compromised due to risk of keyloggers and password theft

Engineering Contradiction:
Improveauthentication securityVSAvoidpassword theft risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a mobile device as an intermediary between the user and the public computer terminal. The mobile device stores the user's credentials and communicates authentication information wirelessly to the terminal, eliminating the need for direct password input on the compromised terminal. This intermediary approach transfers the vulnerable authentication process to a secure environment (the user's mobile device) while maintaining access to the public terminal.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/password-based authentication system with a wireless communication-based system. Instead of typing passwords on the terminal's keyboard (which can be monitored by keyloggers), the system uses wireless transmission of authentication tokens from the mobile device to the terminal, substituting the vulnerable mechanical input method with a secure wireless protocol.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If users frequently change passwords to compensate for security risks, then security is improved, but user convenience deteriorates due to frequent password changes and memory burden

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mobile device performs self-service authentication by automatically storing, managing, and transmitting credentials without requiring user intervention. The device handles password storage encryption, wireless communication, and authentication token generation autonomously, eliminating the need for users to manually remember or re-type passwords across different sessions and terminals.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary authentication setup on the secure mobile device before accessing the public terminal. Credentials are pre-stored and encrypted in the mobile device, and authentication tokens are pre-generated and transmitted wirelessly. This preliminary action on a secure device eliminates the need for repeated password entry on vulnerable terminals, reducing the frequency of password changes needed.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If users access multiple accounts on public terminals, then productivity is improved, but security risk increases due to repeated exposure to keyloggers and credential theft

Engineering Contradiction:
Improveaccount access efficiencyVSAvoidcredential exposure risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The mobile device serves as a universal authentication gateway that can access multiple different accounts and services. It stores credentials for various accounts and communicates with different public terminals wirelessly, enabling users to access multiple accounts without repeating the vulnerable password-entry process on each terminal. The mobile device becomes a multi-functional authentication hub that consolidates security across all account access points.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution securely provides logon credentials for public terminals, reducing the risk of password theft and simplifying account access by using a temporary authentication ID that is specific to each session, thus enhancing user convenience and security.

Implementation Method 1

wireless transceiver carried by the portable housing... wirelessly communicate logon data via a wireless communications network

Methodology Applied
Scientific EffectWireless communication: Electromagnetic Induction

Implementation Method 2

The sensor may comprise a near field communication (NFC) sensor

Methodology Applied
Scientific EffectNear field communication: Electromagnetic Induction

Implementation Method 3

cause the display to display an optical pattern representing the temporary authenticated logon ID... cause the optical sensor to read the optical pattern

Methodology Applied
Scientific EffectOptical pattern recognition: Photoelectric Effect

Data Source

PatentEP2421217B1Communication system providing wireless authentication for private data access and related method
Publication Date: 2013.10.02 BLACKBERRY LTD
  • EP2421217B1 patent drawingFigure 1
  • EP2421217B1 patent drawingFigure 2
  • EP2421217B1 patent drawingFigure 3

AI summary

A communication system may include a server configured to provide data access based upon an authenticated logon, and a computer configured to access the server to receive a temporary authenticated logon identification (ID) for the server. The communication system may further include a mobile wireless communications device including a housing, a wireless transceiver carried by the housing, a sensor carried by the housing, and a controller carried by the housing, the controller being coupled to the wireless transceiver and the sensor. The controller may be configured to cause the sensor to wirelessly retrieve the temporary authenticated logon ID from the computer, and cause the wireless transceiver to wirelessly communicate logon data to the server for providing data access via the computer based upon the temporary authenticated logon ID.