Preemptive Mobile Authentication Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current multi-factor authentication methods are cumbersome and require significant infrastructure, limiting their adoption beyond niche user bases, and raise privacy concerns due to the need for location data storage on central servers.

Innovation Solution

A system that leverages modern mobile devices' network connectivity and location awareness to provide an automated, unobtrusive second factor of authentication, allowing users to automate permission responses based on predefined criteria such as location, eliminating the need for repeated manual input and reducing infrastructure requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware security tokens are used for multi-factor authentication, then authentication security is improved, but device complexity and infrastructure requirements increase significantly

Engineering Contradiction:
Improveauthentication securityVSAvoidinfrastructure requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces physical hardware tokens with software-based authentication mechanisms that replicate the security functionality of hardware tokens using mobile devices. The system uses cryptographic protocols and secure software implementations to copy the essential security functions of hardware tokens, eliminating the need for specialized physical devices while maintaining authentication security.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent substitutes mechanical/physical hardware tokens with software-based solutions running on mobile devices. Instead of requiring physical hardware components, the system uses software applications, cryptographic algorithms, and network communication to achieve the same authentication security, thereby reducing infrastructure complexity and hardware costs.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Device complexity

If software-based tokens on mobile devices are used, then infrastructure requirements are reduced, but user convenience deteriorates due to manual code transcription

Engineering Contradiction:
Improveinfrastructure requirementsVSAvoiduser convenience
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The patent implements automated authentication workflows where the mobile device application automatically performs authentication actions without requiring manual user intervention. The system captures authentication codes automatically, handles the authentication communication with servers, and completes the verification process autonomously, allowing the device to serve itself in the authentication process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent pre-configures the mobile device application with authentication credentials, cryptographic keys, and server information before authentication is needed. The application maintains persistent sessions and pre-establishes communication channels, so when authentication is required, the process can proceed automatically without requiring users to manually input codes or re-enter information.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If location data is stored on central servers for authentication, then authentication capability is improved, but user privacy concerns increase due to data storage on third-party servers

Engineering Contradiction:
Improveauthentication capabilityVSAvoidprivacy concerns
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts location data processing from central servers and relocates it to the user's mobile device. The system retrieves location information locally from the device's GPS and other sensors, processes it client-side, and uses it for authentication decisions without transmitting the raw location data to external servers, thereby maintaining authentication capability while protecting user privacy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces the mobile device as an intermediary between the authentication system and location data. Instead of servers directly accessing and storing user location information, the mobile device acts as a mediator that collects location data locally, processes it through authentication logic, and only communicates authentication results with servers, preventing direct exposure of sensitive location data to third parties.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10212588B2Preemptive authorization automation
Publication Date: 2019.02.19 SALESFORCE INC
  • US10212588B2 patent drawing
  • US10212588B2 patent drawing
  • US10212588B2 patent drawing

AI summary

Techniques are disclosed relating to automating permission requests, e.g., in the context of multi-factor authentication. In some embodiments, based on a change in one or more automation criteria (e.g., based on a mobile device entering a particular geographic region) a mobile device is configured to preemptively indicate to an authorization system to automatically authorize a subsequent attempt to perform an action, without transmitting the permission request to the mobile device. The mobile device may later revoke the preemptive permission request, e.g., based on another change in automation criteria. Disclosed techniques may increase authorization security while reducing user interaction for multi-factor authentication, in some embodiments.