Proximity-Based Authentication for Secure Browser Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional user authentication methods for secure Internet browsers are often time-consuming, error-prone, and susceptible to insecure credential management and unauthorized access due to the need for users to remember and manage credentials.

Innovation Solution

A proximity-based authentication system using short-range communication protocols to identify and authenticate user devices within a defined range, allowing secure access to Internet browser functions without requiring users to manually input credentials, and automatically locking sessions when the device moves out of range.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional authentication methods requiring manual credential entry are used, then users can access secure functions, but the authentication process becomes time-consuming and error-prone

Engineering Contradiction:
Improveauthentication processVSAvoidauthentication time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by establishing proximity-based authentication credentials in advance through short-range communication protocols. When a user device is detected within the defined range of the secure computing device, the authentication state is pre-established, eliminating the need for manual credential entry at the moment of access, thus reducing authentication time and improving ease of operation.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional credential management is used, then users can access applications, but security is compromised due to insecure credential management and potential interception

Engineering Contradiction:
Improveauthentication securityVSAvoidunauthorized access risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces short-range communication protocols as an intermediary mechanism for authentication. Instead of directly transmitting or storing traditional credentials that are vulnerable to interception, the system uses proximity-based communication channels (such as NFC, Bluetooth Low Energy, or other SRC protocols) to establish authentication. This intermediary layer enhances security by leveraging the inherent security properties of short-range communication, making credential interception and unauthorized access significantly more difficult.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If manual credential entry is required, then access control can be implemented, but user convenience is reduced and errors increase

Engineering Contradiction:
Improveaccess control processVSAvoidauthentication accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements self-service authentication where the user device automatically performs authentication functions without requiring manual user input. The proximity-based authentication mechanism automatically detects the user device, verifies credentials through short-range communication, and grants or denies access without user intervention. This eliminates manual credential entry errors while maintaining access control, significantly improving both ease of operation and authentication accuracy.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10909268B2Proximity-based user authentication for providing a webpage of an access-controlled application
Publication Date: 2021.02.02 FISERV INC
  • US10909268B2 patent drawing
  • US10909268B2 patent drawing
  • US10909268B2 patent drawing

AI summary

Example embodiments relate to controlling secured access to electronically provided application functionality or content. An Internet browser executing on a first computing device initiates periodic polling of a paired second computing device associated with a user for measurements of short range communication protocol signal strength of the second computing device and determines that the second computing device is within an authentication distance of the first computing device. The secure Internet browser transmits an authentication request comprising a device identifier of the second computing device. Responsive to transmitting the authentication request, the secure Internet browser receives an authentication response indicating authentication confirmation, and responsive thereto, the secure Internet browser provides access to a controlled-access application by transmitting a request to a content server for a presentation of the controlled-access application, receiving from the content server a presentation associated with the user, and directing display of the presentation via a user interface.