Secure Session Sharing via Machine-Readable Code Proximity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for sharing user authentication data between computing devices are vulnerable to interception and hacking, particularly when authorizing access between devices connected to the same network.

Innovation Solution

A method that transfers a machine-readable code (MRC) between authenticated and non-authenticated devices to verify their physical proximity, allowing secure access to secure user content without requiring a second login, using QR codes, sound codes, or near-field communication codes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user authentication data is shared between devices connected to the same network, then access convenience is improved, but security is worsened due to interception and hacking risks

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a machine-readable code (MRC) as an intermediary element that mediates the authentication process between devices. Instead of directly sharing sensitive authentication data over the network, the system uses MRC as a secure intermediary that can be physically scanned or read, thereby maintaining convenience while enhancing security through physical proximity verification

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional network-based electronic authentication mechanisms with a physical verification mechanism using machine-readable codes. This substitution introduces a physical layer (scanning, visual verification) into the authentication process, making it resistant to network-based attacks while maintaining ease of access

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If session sharing is authorized based on network connection, then device compatibility is improved, but security is worsened due to susceptibility to hacking and malware

Engineering Contradiction:
Improvedevice compatibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary verification by requiring physical proximity confirmation through machine-readable code exchange before authorizing session sharing. This preliminary action ensures that only devices physically present near the user can access the session, preventing unauthorized access while maintaining broad device compatibility

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies local quality by making the authentication requirement specific to the local physical context. The machine-readable code verification ensures that session sharing is authorized based on local physical proximity rather than global network connectivity, thereby enhancing security while maintaining adaptability across different device types

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11706219B1Secure session sharing between computing devices
Publication Date: 2023.07.18 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US11706219B1 patent drawing
  • US11706219B1 patent drawing
  • US11706219B1 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for authenticating a first computing device to access a secure account. Receiving a request from a second computing device to be authorized to access the secure account. Providing, to the second computing, first data that represents a first machine-readable code for presentation by the second computing device. Receiving, from the first computing device, second data that represents a second machine-readable code as read by the first computing device. Authorizing the second computing device to access the secure account in response to determining that the second data accurately represents the first machine-readable code as sent to the second computing device.