Pre-authentication Sequence for Mobile Device Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile device authentication mechanisms are vulnerable to unauthorized access when users enter authentication information in public places, as others can observe the input, allowing potential thieves to replicate the entry and gain access to the device.
Innovation Solution
A pre-authentication mechanism that allows users to define sequences of device movements, screen taps, or key presses, which must be correctly entered to access the main authentication screen, with multiple sequences and corresponding sleep time thresholds or authentication information, enhancing security by requiring specific actions or information based on the device's sleep time or defined sequences.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional authentication mechanisms are used where users enter passwords on the display, then the authentication process is simple and quick, but the security is compromised in public places where shoulder surfing can occur
Solution Approach 1:
The patent applies preliminary action by requiring the user to perform specific physical actions (such as picking up the device, rotating it, or pressing specific buttons) before the authentication screen becomes accessible. These pre-authentication actions establish a preliminary security barrier that prevents unauthorized access even if the password is observed, as the attacker cannot replicate the specific sequence of physical actions without prior knowledge of the user's habits.
Solution Approach 2:
The authentication process is segmented into multiple distinct stages: first the pre-authentication physical actions must be completed, then the password entry screen becomes available. This segmentation separates the physical context authentication from the cryptographic authentication, ensuring that both barriers must be overcome for access to be granted, thereby maintaining security while keeping each individual step simple.
2Reliability
If multiple pre-authentication sequences with different sleep time thresholds are implemented, then security is enhanced by adapting to different usage scenarios, but the device complexity increases
Solution Approach 1:
The system dynamically adjusts the pre-authentication sequence requirements based on the device's sleep time and usage scenario. Instead of using a fixed authentication method, the system adapts its security requirements in real-time - for example, requiring a different physical action sequence if the device has been asleep for a long period versus a short period. This dynamic adaptation enhances security without requiring complex manual configuration, as the system automatically determines the appropriate authentication level.
Solution Approach 2:
The patent changes the parameter of authentication requirements based on the sleep time parameter. Different sleep time thresholds trigger different pre-authentication sequences, effectively using parameter changes (sleep time) to control the security level. This approach allows the system to maintain high security for prolonged absences while reducing friction for quick pick-ups, all through automated parameter-based decision-making rather than complex user configuration.
Data Source
AI summary
A mobile device includes a pre-authentication mechanism that allows a user to define a pre-authentication sequence that includes actions such as movement of the device, taps on the screen, key presses, etc., or any suitable combination of these. Correctly entering the pre-authentication sequence gives the user access to the main authentication screen for the device, while a failure to enter the pre-authentication sequence correctly keeps the device locked. Multiple pre-authentication sequences can be defined, each having a corresponding sleep time threshold. This requires the user to enter the appropriate authentication information corresponding to the time the device has been asleep. Multiple pre-authentication sequences can also be defined, each having corresponding authentication information. Thus, the authentication information the user needs to enter can be a function of the corresponding pre-authentication sequence.


