Push Notification Authentication for Password-Free Account Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face inefficiencies and complexities in managing multiple online passwords, often forgetting or reusing them, which can lead to time-consuming and insecure access to online accounts.

Innovation Solution

A two-factor authentication system that eliminates the need for password entry by using an addressable handle and a security code associated with a financial account, leveraging push notifications to authenticate users securely without requiring password input.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users manage and remember multiple passwords with complexity and regular changes, then security is improved, but time consumption and operational complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the password verification function from the login process and replaces it with push notification-based authentication. The system sends a push notification to the user's mobile device containing a security code, eliminating the need for users to remember or enter passwords while maintaining security through device-based verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a mobile device as an intermediary between the user and the authentication system. Instead of requiring direct password entry, the system uses push notifications delivered to the mobile device as a mediator to verify user identity, thereby reducing the burden on users while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If users use the same password for multiple accounts to simplify management, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improveease of password managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent removes the password element from the authentication process entirely and replaces it with push notification-based verification. This extraction eliminates the need for users to manage multiple passwords or reuse them, as authentication is performed through device-based push notifications that do not require password knowledge.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If users change passwords regularly to maintain security, then security is improved, but time consumption and operational complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the password change requirement from the authentication process and replaces it with push notification-based verification. The system maintains security through regular verification of user identity via push notifications to registered devices, eliminating the need for users to manually change passwords while preserving security standards.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9912648B2Two-factor authentication with push notification for a security code
Publication Date: 2018.03.06 BLOCK INC
  • US9912648B2 patent drawing
  • US9912648B2 patent drawing
  • US9912648B2 patent drawing

AI summary

Disclosed is a technology for password-free account authentication. The technology includes utilizing a mobile device running an application (“App”) associated with a payment service (PS) system. Using the App, a user can enter an addressable handle, which is transmitted to the PS system. The PS system identifies an account state, based on the receipt of the addressable handle, for example, whether the addressable handle corresponds to a user's system account and device. A first authentication factor is based on the knowledge that the user is in possession of and has access to a device that corresponds to the user and the addressable handle. The PS system pushes a notification to the corresponding device, based on the account state, prompting entry of a security code. Receipt of a security code that corresponds to a payment card linked to the user's system account serves as a second authentication factor.