Mobile Wireless Authentication via Temporary Logon ID
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face security risks when accessing public or shared computer terminals due to the risk of keyloggers compromising passwords, leading to the need for frequent password changes and inconvenience in managing multiple passwords across different accounts.
Innovation Solution
A communication system that includes a mobile wireless communications device with a wireless transceiver and sensor, which retrieves a temporary authenticated logon ID from a computer terminal and communicates it via NFC or optical patterns to securely authenticate access to a server, eliminating the need for direct password input and reducing the risk of password compromise.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users input passwords directly on public computer terminals, then authentication is completed, but security risk increases due to keylogger exposure
Solution Approach 1:
The patent extracts the password input operation from the public computer terminal and relocates it to the user's mobile device. The mobile device displays a password confirmation screen where the user enters the password locally, preventing direct password input on the public terminal and eliminating keylogger exposure risk.
Solution Approach 2:
The patent introduces a mobile device as an intermediary between the user and the public computer terminal. The mobile device acts as a secure mediator that handles password input and transmits only a confirmation signal to the terminal, preventing direct exposure of the password to potential keyloggers on the public terminal.
2Adaptability or versatility
If users manage multiple passwords for different accounts, then access to multiple accounts is enabled, but operational complexity and time consumption increase
Solution Approach 1:
The patent implements a universal authentication mechanism where a single mobile device can authenticate access to multiple different accounts and services. The mobile device serves as a universal key that replaces the need to manage multiple passwords, enabling the user to access various accounts through one authentication device.
Solution Approach 2:
The patent merges multiple authentication functions into a single mobile device. Instead of requiring separate password management for each account, the mobile device combines all authentication capabilities into one unified system, eliminating the need to remember and manage multiple passwords.
3Reliability
If frequent password changes are implemented, then security against keyloggers is improved, but user convenience and operational efficiency deteriorate
Solution Approach 1:
The patent extracts the password change operation from the public computer terminal and relocates it to the mobile device. Password changes are performed locally on the mobile device through secure communication with the account server, eliminating the need to repeatedly change passwords on public terminals and maintaining security without sacrificing convenience.
Solution Approach 2:
The patent enables self-service password management through the mobile device. The mobile device autonomously handles password storage, updates, and authentication without requiring user interaction with public computer terminals for password management operations, providing both security and convenience.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This solution provides secure and convenient access to private data accounts by using a temporary authentication ID, reducing the burden of managing multiple passwords and minimizing the risk of password theft from keyloggers, while allowing users to access multiple accounts with a single authentication method.
Implementation Method 1
The sensor may comprise a near field communication (NFC) sensor, and the computer and NFC sensor may be configured to communicate the temporary authenticated logon ID therebetween via NFC communications
Implementation Method 2
the computer may be further configured to cause the display to display an optical pattern representing the temporary authenticated logon ID. Further, the sensor may comprise an optical sensor, and the controller may be further configured to cause the optical sensor to read the optical pattern from the display and determine the temporary authenticated logon ID therefrom
Data Source
AI summary
A communication system may include a server configured to provide data access based upon an authenticated logon, and a computer configured to access the server to receive a temporary authenticated logon identification (ID) for the server. The communication system may further include a mobile wireless communications device including a housing, a wireless transceiver carried by the housing, a sensor carried by the housing, and a controller carried by the housing, the controller being coupled to the wireless transceiver and the sensor. The controller may be configured to cause the sensor to wirelessly retrieve the temporary authenticated logon ID from the computer, and cause the wireless transceiver to wirelessly communicate logon data to the server for providing data access via the computer based upon the temporary authenticated logon ID.


