Optical Key Capture for Authentication Device Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing web service systems face inefficiencies and user errors in authenticating devices, particularly when requiring manual input of keys or codes, which can lead to authentication failures and security vulnerabilities.

Innovation Solution

A web services system provisions a device as an authentication device by displaying an image containing a key or challenge code, allowing the device to capture and extract the information, which is then used to generate one-time passcodes or respond to authorization requests, thereby reducing user error and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual input of keys or codes is required for authentication, then user interaction is necessary, but authentication failures and security vulnerabilities increase due to user errors

Engineering Contradiction:
Improvemanual input processVSAvoidauthentication success rate
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the manual mechanical input process with an automated optical system. The authentication device captures images of keys or challenge codes displayed on a screen and automatically extracts the required information, eliminating the need for manual typing or entry and thereby reducing user errors that lead to authentication failures

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The authentication device performs self-service by automatically capturing and extracting key information or challenge codes from displayed images without requiring user intervention for manual input. The device independently completes the authentication data collection process, improving both ease of operation and reliability

Inventive Principle:
Principle #25Self-service

2Reliability

If automated image capture and extraction is implemented, then user error is reduced, but device complexity increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidauthentication device functionality
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication device leverages existing multi-functional capabilities of mobile devices, using the camera for image capture, the processor for extracting key information or challenge codes, and the communication module for transmitting data. This approach achieves automated authentication without requiring dedicated specialized hardware, thereby limiting the increase in device complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary display screen that presents keys or challenge codes in visual form, serving as a bridge between the authentication system and the user's device. This intermediary allows the authentication device to capture and process information automatically without direct user manipulation, improving accuracy while keeping the overall system architecture relatively simple

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12113788B2Provisioning a device to be an authentication device
Publication Date: 2024.10.08 AMAZON TECH INC
  • US12113788B2 patent drawing
  • US12113788B2 patent drawing
  • US12113788B2 patent drawing

AI summary

In certain embodiments, a web services system receives a request to provision a device, such as a telephone, as an authentication device. The web services system initiates display of an image communicating a key to allow the telephone to capture the image and to send key information associated with the key. The web services system receives the key and determines that the key information is valid. In response to the determination, the web services system sends a seed to the telephone to provision the telephone to be an authentication device. The telephone can use the seed to generate one-time passcodes to access a service of the web services system.