QR-Based Two-Factor Authentication for Remote Service Login

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional user authentication methods for streaming services, such as those used on smart TVs and set-top boxes, are often cumbersome and insecure, requiring users to input complex passwords or codes via remote controls, which is tedious and inefficient.

Innovation Solution

A method involving the use of a machine-readable QR code displayed on the user device, captured by a mobile device to extract a session code, with the mobile device either sending a stored phone token or prompting for credentials, which are then verified by the remote service to grant access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional username-password authentication is used, then security is maintained, but user-friendliness deteriorates due to complex password input requirements

Engineering Contradiction:
Improveuser-friendlinessVSAvoidauthentication complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a mobile device as an intermediary between the user and the streaming service authentication system. The mobile device captures a QR code displayed on the TV screen, extracts the embedded authentication token, and automatically transmits it to the service provider. This intermediary mechanism eliminates the need for users to manually input complex passwords or codes using the remote control, thereby improving ease of operation while maintaining security through token-based verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If SMS-based two-factor authentication is used, then security is improved, but ease of operation deteriorates as users must still enter credentials via remote control

Engineering Contradiction:
ImprovesecurityVSAvoidease of authentication
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a self-service authentication mechanism where the mobile device automatically performs all authentication operations without requiring manual credential entry. The device captures the QR code, extracts the token, and sends it to the service provider automatically. This self-service approach maintains the security benefits of two-factor authentication while eliminating the tedious step of manually entering codes or credentials through the remote control interface.

Inventive Principle:
Principle #25Self-service

3Reliability

If manual code entry via remote control is required, then authentication security is maintained, but productivity deteriorates due to tedious and time-consuming input process

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces the mechanical interaction of manually pressing remote control buttons to enter codes with an automated optical and electronic system. The mobile device uses its camera to capture the QR code visually, automatically extracts the embedded token through image processing, and transmits it electronically to the service provider. This substitution of mechanical input with automated optical-electronic processes dramatically increases authentication speed while maintaining security through the same token verification mechanism.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250392590A1Code-based two factor authentication
Publication Date: 2025.12.25 SONY GROUP CORP
  • US20250392590A1 patent drawing
  • US20250392590A1 patent drawing
  • US20250392590A1 patent drawing

AI summary

Authenticating a user account to access a remote service from a user device includes: capturing a machine-readable image code displayed on the user device using a mobile device, wherein the image code is provided by the remote service; extracting and calling a corresponding session code embedded in the image code; determining whether a phone token is in storage; one of: (a) sending the phone token to the remote service, if the phone token is in the storage; or (b) prompting a user to enter credentials including username and password and sending the entered credentials to the remote service, if the phone token is not in the storage; and receiving access to the remote service for the user device, when the session code is valid and either the credentials are valid or the phone token is confirmed.