Multi-Device Authentication Token Generation for Deprecated Browsers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Deprecated browsers, commonly used on devices like gaming consoles, lack security features and user-friendly interfaces for online transactions, posing security concerns and usability issues for sensitive data input.
Innovation Solution
A multi-device and multi-factor authentication system that communicates with user devices and online merchants to authenticate users without requiring sensitive information input through a deprecated browser, using a trusted device to generate and transmit tokens for secure transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If deprecated browsers are used on devices like gaming consoles, then device compatibility and accessibility are improved, but security features and data protection are worsened
Solution Approach 1:
The patent introduces a trusted device as an intermediary that handles sensitive authentication operations. The deprecated browser acts only as a display device showing QR codes or authentication requests, while the trusted device (mobile phone, tablet, or computer) performs the actual authentication through secure browsers, eliminating the need for the deprecated browser to have security features
Solution Approach 2:
The authentication system is segmented into multiple components: the deprecated browser displays authentication requests, the trusted device handles secure authentication operations, and the server validates credentials. This segmentation allows each component to perform its specific function without requiring all components to have full security capabilities
2Ease of operation
If deprecated browsers are used for online transactions, then accessibility to devices without modern browsers is improved, but security risks for sensitive data input are worsened
Solution Approach 1:
A trusted device serves as a mediator between the user and the deprecated browser. The user interacts with the deprecated browser by scanning QR codes or viewing authentication requests, but the actual sensitive data input and authentication occur on the trusted device with a secure browser, transferring the security burden from the deprecated browser to the trusted device
Solution Approach 2:
The system creates a copy of the authentication interface on the trusted device. Instead of requiring the deprecated browser to handle sensitive data directly, the authentication request is copied to the trusted device where it can be processed securely, and the result is then communicated back to the deprecated browser
3Reliability
If multi-device authentication is implemented, then security is improved, but system complexity is worsened
Solution Approach 1:
The server implements a universal authentication mechanism that works across multiple device types (deprecated browsers, mobile phones, tablets, computers) through a common protocol. The server recognizes authenticated sessions from any trusted device and can generate tokens for use on any device, creating a multi-functional system that handles diverse devices through a unified approach
Data Source
AI summary
Disclosed herein are methods and systems for electronic authentication including receiving a purchase request from a browser application executing on a first electronic device; determining a user identifier associated with the purchase request; responsive to determining that the browser application does not satisfy a security threshold, identifying an active authenticated session for the user identifier, wherein the active authenticated session was generated using a second electronic device of a set of pre-authorized devices associated with the user identifier; generating a token for the purchase request before an expiration of the active authenticated session; and authorizing the purchase request using the token.


