Multi-Device Authentication via Primary Device Credential Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user authentication methods for online services often require additional equipment or manual input of authentication codes, compromising ease and security, especially when using multiple devices.
Innovation Solution
A method that utilizes a primary device for secure credential storage and authentication, allowing users to log in to online services via secondary devices without exposing credentials on those devices, using a verification code to confirm authentication and ensuring only trusted primary devices are used for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multi-factor authentication is implemented using smartcards or USB sticks, then security is improved, but device complexity and portability requirements worsen
Solution Approach 1:
The patent applies universality by enabling the authentication system to work across multiple device types (smartphones, tablets, computers) without requiring device-specific hardware like smartcards or USB sticks. The primary device serves as a universal authentication token that can be used with any online service, eliminating the need for users to carry or insert additional equipment.
Solution Approach 2:
The patent replaces mechanical authentication systems (physical smartcards, USB sticks that must be inserted into devices) with an electronic/digital authentication mechanism. The verification code is transmitted electronically between devices, eliminating the need for physical insertion or manual code entry, thus reducing device complexity while maintaining security.
2Reliability
If authentication codes are sent via SMS to mobile phones, then security is improved, but ease of operation worsens due to manual input requirements
Solution Approach 1:
The patent replaces manual input of authentication codes with automatic electronic transmission. Instead of users receiving SMS codes and manually typing them, the verification code is automatically transmitted from the online service through the secondary device to the primary device, and the authentication response is automatically sent back, eliminating manual input entirely.
Solution Approach 2:
The system performs self-service authentication where the primary device automatically handles the verification process. The user simply initiates authentication on the secondary device, and the primary device autonomously receives the verification code, validates it, and sends the authentication response without requiring user intervention beyond the initial request.
3Adaptability or versatility
If FIDO alliance standards are implemented with multiple devices, then accessibility is improved, but device complexity and setup requirements worsen
Solution Approach 1:
The patent achieves universality by designing the primary device to serve as a single authentication token that works across multiple online services and can be accessed from multiple secondary devices. The system automatically manages the binding between primary and secondary devices without requiring manual configuration on each device, thus providing multi-device access without increasing complexity.
Solution Approach 2:
The patent introduces the online service as an intermediary that facilitates the binding between primary and secondary devices. Instead of requiring direct manual configuration between devices, the online service mediates the association process, automatically linking the verification code sent to the primary device with the corresponding secondary device, thus simplifying multi-device setup.
4Ease of operation
If credentials are stored on secondary devices for login, then ease of operation is improved, but security worsens due to credential exposure
Solution Approach 1:
The patent extracts the credentials from the secondary device and stores them exclusively in the primary device. The secondary device only handles the verification code transmission and authentication request, while the actual credentials (authentication response) remain secured in the primary device. This separation ensures credentials are not exposed on potentially insecure secondary devices while maintaining operational convenience.
Solution Approach 2:
The online service acts as an intermediary that facilitates authentication without requiring credentials to be stored on the secondary device. The system uses the verification code as a temporary mediator that proves the user's identity without exposing actual credentials, allowing convenient login on secondary devices while maintaining credential security in the primary device.
Data Source
Figure 1~2
Figure 3
AI summary
The invention refers to a method for authenticating a user (U) when logging in at an online service (OS), where the online service (OS) is provided by a server arrangement and the method is based on a communication between the online service (OS) and a primary device (PD) and between the online service (OS) and a secondary device (SD), the method comprising the following steps: a) a user identification (ID) specified by the user (U) at the secondary device (SD) and not including any creden- tial is received by the online service (OS); b) an authentication request (ARE) is transmitted by the online service (OS) to the primary device (PD) where the primary device (PD) is associated with the user identification (ID); c) an authentication response (ARS) comprising at least one credential (CR) is transmitted by the primary device (PD) to the online service (OS), where the at least one credential (CR) originates from a storage in the primary device (PD) and is only transmitted through the authentication response (ARS) upon a successful local authentication of the user (U) at the primary device (PD) or where the at least one credential (CR) is specified by the user (U) at the primary device (PD); d) in case of a successful verification of the at least one credential (CR) by the online service (OS), the user (U) is logged in at the online service (OS) and a confirmation (CON) of the login is sent to the secondary device (SD).