Preemptive Mobile Authentication Automation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current multi-factor authentication methods are cumbersome and require significant infrastructure, limiting their adoption beyond niche user bases, and raise privacy concerns due to the need for location data storage on central servers.
Innovation Solution
A system that leverages modern mobile devices' network connectivity and location awareness to provide an automated, unobtrusive second factor of authentication, allowing users to automate permission responses based on predefined criteria such as location, eliminating the need for repeated manual input and reducing infrastructure requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware security tokens are used for multi-factor authentication, then authentication security is improved, but device complexity and infrastructure requirements increase significantly
Solution Approach 1:
The patent replaces physical hardware tokens with software-based authentication mechanisms that replicate the security functionality of hardware tokens using mobile devices. The system uses cryptographic protocols and secure software implementations to copy the essential security functions of hardware tokens, eliminating the need for specialized physical devices while maintaining authentication security.
Solution Approach 2:
The patent substitutes mechanical/physical hardware tokens with software-based solutions running on mobile devices. Instead of requiring physical hardware components, the system uses software applications, cryptographic algorithms, and network communication to achieve the same authentication security, thereby reducing infrastructure complexity and hardware costs.
2Device complexity
If software-based tokens on mobile devices are used, then infrastructure requirements are reduced, but user convenience deteriorates due to manual code transcription
Solution Approach 1:
The patent implements automated authentication workflows where the mobile device application automatically performs authentication actions without requiring manual user intervention. The system captures authentication codes automatically, handles the authentication communication with servers, and completes the verification process autonomously, allowing the device to serve itself in the authentication process.
Solution Approach 2:
The patent pre-configures the mobile device application with authentication credentials, cryptographic keys, and server information before authentication is needed. The application maintains persistent sessions and pre-establishes communication channels, so when authentication is required, the process can proceed automatically without requiring users to manually input codes or re-enter information.
3Reliability
If location data is stored on central servers for authentication, then authentication capability is improved, but user privacy concerns increase due to data storage on third-party servers
Solution Approach 1:
The patent extracts location data processing from central servers and relocates it to the user's mobile device. The system retrieves location information locally from the device's GPS and other sensors, processes it client-side, and uses it for authentication decisions without transmitting the raw location data to external servers, thereby maintaining authentication capability while protecting user privacy.
Solution Approach 2:
The patent introduces the mobile device as an intermediary between the authentication system and location data. Instead of servers directly accessing and storing user location information, the mobile device acts as a mediator that collects location data locally, processes it through authentication logic, and only communicates authentication results with servers, preventing direct exposure of sensitive location data to third parties.
Data Source
AI summary
Techniques are disclosed relating to automating permission requests, e.g., in the context of multi-factor authentication. In some embodiments, based on a change in one or more automation criteria (e.g., based on a mobile device entering a particular geographic region) a mobile device is configured to preemptively indicate to an authorization system to automatically authorize a subsequent attempt to perform an action, without transmitting the permission request to the mobile device. The mobile device may later revoke the preemptive permission request, e.g., based on another change in automation criteria. Disclosed techniques may increase authorization security while reducing user interaction for multi-factor authentication, in some embodiments.


