Mobile Wireless Authentication via Temporary Logon ID

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face security risks when accessing public or shared computer terminals due to the risk of keyloggers compromising passwords, leading to the need for frequent password changes and inconvenience in managing multiple passwords across different accounts.

Innovation Solution

A communication system that includes a mobile wireless communications device with a wireless transceiver and sensor, which retrieves a temporary authenticated logon ID from a computer terminal and communicates it via NFC or optical patterns to securely authenticate access to a server, eliminating the need for direct password input and reducing the risk of password compromise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users input passwords directly on public computer terminals, then authentication is completed, but security risk increases due to keylogger exposure

Engineering Contradiction:
Improveauthentication securityVSAvoidkeylogger exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the password input operation from the public computer terminal and relocates it to the user's mobile device. The mobile device displays a password confirmation screen where the user enters the password locally, preventing direct password input on the public terminal and eliminating keylogger exposure risk.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a mobile device as an intermediary between the user and the public computer terminal. The mobile device acts as a secure mediator that handles password input and transmits only a confirmation signal to the terminal, preventing direct exposure of the password to potential keyloggers on the public terminal.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If users manage multiple passwords for different accounts, then access to multiple accounts is enabled, but operational complexity and time consumption increase

Engineering Contradiction:
Improvemulti-account access capabilityVSAvoidpassword management time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements a universal authentication mechanism where a single mobile device can authenticate access to multiple different accounts and services. The mobile device serves as a universal key that replaces the need to manage multiple passwords, enabling the user to access various accounts through one authentication device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges multiple authentication functions into a single mobile device. Instead of requiring separate password management for each account, the mobile device combines all authentication capabilities into one unified system, eliminating the need to remember and manage multiple passwords.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If frequent password changes are implemented, then security against keyloggers is improved, but user convenience and operational efficiency deteriorate

Engineering Contradiction:
Improvepassword securityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the password change operation from the public computer terminal and relocates it to the mobile device. Password changes are performed locally on the mobile device through secure communication with the account server, eliminating the need to repeatedly change passwords on public terminals and maintaining security without sacrificing convenience.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent enables self-service password management through the mobile device. The mobile device autonomously handles password storage, updates, and authentication without requiring user interaction with public computer terminals for password management operations, providing both security and convenience.

Inventive Principle:
Principle #25Self-service

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution provides secure and convenient access to private data accounts by using a temporary authentication ID, reducing the burden of managing multiple passwords and minimizing the risk of password theft from keyloggers, while allowing users to access multiple accounts with a single authentication method.

Implementation Method 1

The sensor may comprise a near field communication (NFC) sensor, and the computer and NFC sensor may be configured to communicate the temporary authenticated logon ID therebetween via NFC communications

Methodology Applied
Scientific EffectNFC (Near Field Communication): Electromagnetic Induction

Implementation Method 2

the computer may be further configured to cause the display to display an optical pattern representing the temporary authenticated logon ID. Further, the sensor may comprise an optical sensor, and the controller may be further configured to cause the optical sensor to read the optical pattern from the display and determine the temporary authenticated logon ID therefrom

Methodology Applied
Scientific EffectOptical detection: Photoelectric Effect

Data Source

PatentUS8869248B2Communication system providing wireless authentication for private data access and related methods
Publication Date: 2014.10.21 MALIKIE INNOVATIONS LTD
  • US8869248B2 patent drawing
  • US8869248B2 patent drawing
  • US8869248B2 patent drawing

AI summary

A communication system may include a server configured to provide data access based upon an authenticated logon, and a computer configured to access the server to receive a temporary authenticated logon identification (ID) for the server. The communication system may further include a mobile wireless communications device including a housing, a wireless transceiver carried by the housing, a sensor carried by the housing, and a controller carried by the housing, the controller being coupled to the wireless transceiver and the sensor. The controller may be configured to cause the sensor to wirelessly retrieve the temporary authenticated logon ID from the computer, and cause the wireless transceiver to wirelessly communicate logon data to the server for providing data access via the computer based upon the temporary authenticated logon ID.