Secure Browser Instance for Mobile Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional multi-factor authentication methods, particularly those using SMS-based pin verification, are vulnerable to interception and unauthorized access due to lack of protection, allowing unauthorized users to compromise the authentication process even with limited access to the device.

Innovation Solution

A secure device authentication system that initiates a secure browser instance on the mobile device, providing a single-action link through SMS or other mediums, ensuring that authentication actions are performed within a trusted environment, using session tokens and device-specific identifiers to verify the device's identity and prevent duplication or hijacking.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If SMS-based pin verification is used for authentication, then ease of operation is improved, but security is worsened due to vulnerability to interception and unauthorized access

Engineering Contradiction:
Improveauthentication processVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a secure browser instance as an intermediary component between the SMS message reception and the authentication action. This secure browser acts as a trusted mediator that verifies the authenticity of authentication links before allowing user interaction, thereby maintaining ease of operation while improving security against interception and unauthorized access

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary verification actions by checking whether the authentication link originates from a trusted source before allowing the user to proceed with authentication. This preliminary check prevents unauthorized authentication attempts while maintaining the simple SMS-based workflow for legitimate users

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a secure browser instance with verification processes is implemented, then security is improved, but device complexity is worsened

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into distinct functional components: the secure browser instance, the verification process, and the authentication execution. This segmentation allows each component to perform its specific security function independently, improving overall security while managing complexity through modular design

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9706402B2System and method for secure device authentication
Publication Date: 2017.07.11 NEUSTAR INC
  • US9706402B2 patent drawing
  • US9706402B2 patent drawing
  • US9706402B2 patent drawing

AI summary

A method and system for secure authentication of a mobile computing device (MCD) are described. Data that identifies the MCD is obtained. Identification data is exchanged with a network service, which sends embedded data to trigger a secure browser instance on the MCD. A secure single action link specific to the requesting device is then provided, the secure single action link being actionable to communicate to the network service, through the secure browser instance, a session token corresponding to the mobile computing device. The user can perform a selection action on the secure single action link to authenticate the MCD.