Multi-Device Authentication via Primary Device Credential Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication methods for online services often require additional equipment or manual input of authentication codes, compromising ease and security, especially when using multiple devices.

Innovation Solution

A method that utilizes a primary device for secure credential storage and authentication, allowing users to log in to online services via secondary devices without exposing credentials on those devices, using a verification code to confirm authentication and ensuring only trusted primary devices are used for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-factor authentication is implemented using smartcards or USB sticks, then security is improved, but device complexity and portability requirements worsen

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication equipment
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by enabling the authentication system to work across multiple device types (smartphones, tablets, computers) without requiring device-specific hardware like smartcards or USB sticks. The primary device serves as a universal authentication token that can be used with any online service, eliminating the need for users to carry or insert additional equipment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent replaces mechanical authentication systems (physical smartcards, USB sticks that must be inserted into devices) with an electronic/digital authentication mechanism. The verification code is transmitted electronically between devices, eliminating the need for physical insertion or manual code entry, thus reducing device complexity while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If authentication codes are sent via SMS to mobile phones, then security is improved, but ease of operation worsens due to manual input requirements

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces manual input of authentication codes with automatic electronic transmission. Instead of users receiving SMS codes and manually typing them, the verification code is automatically transmitted from the online service through the secondary device to the primary device, and the authentication response is automatically sent back, eliminating manual input entirely.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs self-service authentication where the primary device automatically handles the verification process. The user simply initiates authentication on the secondary device, and the primary device autonomously receives the verification code, validates it, and sends the authentication response without requiring user intervention beyond the initial request.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If FIDO alliance standards are implemented with multiple devices, then accessibility is improved, but device complexity and setup requirements worsen

Engineering Contradiction:
Improvemulti-device accessVSAvoidapp installation and binding
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent achieves universality by designing the primary device to serve as a single authentication token that works across multiple online services and can be accessed from multiple secondary devices. The system automatically manages the binding between primary and secondary devices without requiring manual configuration on each device, thus providing multi-device access without increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces the online service as an intermediary that facilitates the binding between primary and secondary devices. Instead of requiring direct manual configuration between devices, the online service mediates the association process, automatically linking the verification code sent to the primary device with the corresponding secondary device, thus simplifying multi-device setup.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If credentials are stored on secondary devices for login, then ease of operation is improved, but security worsens due to credential exposure

Engineering Contradiction:
Improvelogin convenienceVSAvoidcredential security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the credentials from the secondary device and stores them exclusively in the primary device. The secondary device only handles the verification code transmission and authentication request, while the actual credentials (authentication response) remain secured in the primary device. This separation ensures credentials are not exposed on potentially insecure secondary devices while maintaining operational convenience.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The online service acts as an intermediary that facilitates authentication without requiring credentials to be stored on the secondary device. The system uses the verification code as a temporary mediator that proves the user's identity without exposing actual credentials, allowing convenient login on secondary devices while maintaining credential security in the primary device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3268890B1A method for authenticating a user when logging in at an online service
Publication Date: 2019.05.29 SIEMENS AG
  • EP3268890B1 patent drawingFigure 1~2
  • EP3268890B1 patent drawingFigure 3

AI summary

The invention refers to a method for authenticating a user (U) when logging in at an online service (OS), where the online service (OS) is provided by a server arrangement and the method is based on a communication between the online service (OS) and a primary device (PD) and between the online service (OS) and a secondary device (SD), the method comprising the following steps: a) a user identification (ID) specified by the user (U) at the secondary device (SD) and not including any creden- tial is received by the online service (OS); b) an authentication request (ARE) is transmitted by the online service (OS) to the primary device (PD) where the primary device (PD) is associated with the user identification (ID); c) an authentication response (ARS) comprising at least one credential (CR) is transmitted by the primary device (PD) to the online service (OS), where the at least one credential (CR) originates from a storage in the primary device (PD) and is only transmitted through the authentication response (ARS) upon a successful local authentication of the user (U) at the primary device (PD) or where the at least one credential (CR) is specified by the user (U) at the primary device (PD); d) in case of a successful verification of the at least one credential (CR) by the online service (OS), the user (U) is logged in at the online service (OS) and a confirmation (CON) of the login is sent to the secondary device (SD).