Proximity-Based One Tap Mobile Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote access technologies require multiple steps and additional verification processes, making them less efficient for secure and seamless user authentication, especially in cloud-based environments.

Innovation Solution

A 'one tap' operation using a mobile device app that enables secure login to a computer or cloud account by proximity detection and push notification, integrating with TOTP-based two-factor authentication and leveraging SAML2 protocols for secure cross-origin resource sharing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional remote access authentication is used, then security is maintained through multiple verification steps, but user operation time and complexity increase

Engineering Contradiction:
Improveauthentication securityVSAvoidlogin time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing trust relationships through device pairing and storing authentication credentials locally on the user's device. When login is needed, the pre-configured mobile device can immediately prove identity through proximity detection and stored credentials, eliminating the need for real-time password transmission and multiple verification steps.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary approach by using the mobile device as a trusted mediator between the user and the remote system. The mobile device stores authentication credentials and acts as a secure intermediary that can quickly verify identity through proximity-based communication, reducing the need for complex real-time authentication protocols between the user and remote systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple authentication steps are implemented, then security is enhanced, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidlogin simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service by enabling the mobile device to automatically handle authentication using pre-stored credentials and proximity detection. The mobile device autonomously proves the user's identity to the remote system without requiring the user to manually enter passwords or go through multiple verification steps, making the process as simple as bringing the device near the login terminal.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Authentication credentials and device pairing are performed in advance during an initial setup phase. This preliminary configuration stores security information locally on the user's mobile device, so that subsequent logins require only proximity detection and automatic credential verification, dramatically simplifying the user interaction while maintaining strong security.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If cloud-based remote access is enabled, then accessibility is improved, but security vulnerabilities increase

Engineering Contradiction:
Improveremote access capabilityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by keeping sensitive authentication credentials and security information stored locally on the user's mobile device rather than in centralized cloud repositories. The mobile device itself becomes the secure vault, and proximity-based verification ensures that only authorized devices can access remote systems, reducing the attack surface of cloud-based authentication systems.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The mobile device serves as a secure intermediary that mediates between the user and cloud-based remote access systems. It holds the authentication credentials locally and uses proximity detection to verify legitimate access attempts, acting as a trusted intermediary that reduces reliance on vulnerable cloud-based password systems while enabling widespread remote access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10742648B2Mobile device access to a protected machine
Publication Date: 2020.08.11 GOTO GRP INC
  • US10742648B2 patent drawing
  • US10742648B2 patent drawing
  • US10742648B2 patent drawing

AI summary

In a first embodiment, the “one tap” operation of this disclosure enables a user having a mobile device “one tap” mobile application (or “app”) to log-in to the user's desktop or laptop computer by bringing the user's device in physical proximity to the computer and, while in such proximity, accepting a push notification that is received on the mobile device. In a second embodiment, the user uses the “one tap” functionality to access a cloud-based account that has been set up for the user on a third party web application (e.g., SalesForce.com). The technique seamlessly integrates with third party websites using well-known protocols (e.g., SAML2), and it enables secure cross-origin resource sharing in a highly secure, reliable and available manner. Still another aspect of this disclosure is an enhanced proximity detection routine that is used to facilitate the one tap function when the user's mobile device is moved into proximity with the computer.