Secure Browser Instance for Mobile Device Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional multi-factor authentication methods, particularly those using SMS-based pin verification, are vulnerable to interception and unauthorized access due to lack of protection, allowing unauthorized users to compromise the authentication process even with limited access to the device.
Innovation Solution
A secure device authentication system that initiates a secure browser instance on the mobile device, providing a single-action link through SMS or other mediums, ensuring that authentication actions are performed within a trusted environment, using session tokens and device-specific identifiers to verify the device's identity and prevent duplication or hijacking.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If SMS-based pin verification is used for authentication, then ease of operation is improved, but security is worsened due to vulnerability to interception and unauthorized access
Solution Approach 1:
The patent introduces a secure browser instance as an intermediary component between the SMS message reception and the authentication action. This secure browser acts as a trusted mediator that verifies the authenticity of authentication links before allowing user interaction, thereby maintaining ease of operation while improving security against interception and unauthorized access
Solution Approach 2:
The system performs preliminary verification actions by checking whether the authentication link originates from a trusted source before allowing the user to proceed with authentication. This preliminary check prevents unauthorized authentication attempts while maintaining the simple SMS-based workflow for legitimate users
2Reliability
If a secure browser instance with verification processes is implemented, then security is improved, but device complexity is worsened
Solution Approach 1:
The authentication system is segmented into distinct functional components: the secure browser instance, the verification process, and the authentication execution. This segmentation allows each component to perform its specific security function independently, improving overall security while managing complexity through modular design
Data Source
AI summary
A method and system for secure authentication of a mobile computing device (MCD) are described. Data that identifies the MCD is obtained. Identification data is exchanged with a network service, which sends embedded data to trigger a secure browser instance on the MCD. A secure single action link specific to the requesting device is then provided, the secure single action link being actionable to communicate to the network service, through the secure browser instance, a session token corresponding to the mobile computing device. The user can perform a selection action on the secure single action link to authenticate the MCD.


