Server-Based Visitor Identification for Mobile Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for mobile device authentication and tracking, such as using cookies or IMSI/IMEI numbers, are inadequate for devices with native APIs, particularly in financial service provider contexts, as they do not allow for secure and efficient identification and tracking across multiple visits.

Innovation Solution

A system and method that generates a unique visitor identification for network-based devices, mapping this identification to device-specific information, enabling authentication and tracking without relying on cookies, by using a server computing device to gather and store uniquely identifying user device information, and creating a new visitor identification when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication methods (cookies, IMSI/IMEI) are used, then device identification is possible, but security and efficiency are inadequate for devices with native APIs

Engineering Contradiction:
Improveauthentication securityVSAvoidcompatibility with native APIs
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a server computing device as an intermediary between the mobile device and the network. This server acts as a mediator that receives device information, generates visitor identifications, and maintains mappings between device identifiers and visitor identifications. This intermediary architecture enables secure authentication for devices with native APIs without requiring direct use of conventional methods like cookies or IMSI/IMEI, thus resolving the contradiction between security and API compatibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into distinct functional components: device information gathering, visitor identification generation, mapping maintenance, and tracking. By dividing the authentication process into these separate modules handled by the server computing device, the system achieves both security (through controlled authentication flows) and versatility (through adaptable handling of different device types and API protocols).

Inventive Principle:
Principle #1Segmentation

2Productivity

If device-specific information is tracked across visits, then authentication efficiency improves, but system complexity increases

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidtracking system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The server computing device automatically performs device information gathering, visitor identification generation, and mapping maintenance without requiring complex client-side authentication logic. The mobile device simply provides its native API information, and the server handles all subsequent authentication and tracking operations. This self-service approach on the server side improves authentication efficiency while keeping the client device simple, resolving the contradiction between productivity and complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system creates a virtual representation (visitor identification) of the physical device, storing this copy in the database along with mapping information. This copying mechanism allows efficient tracking and authentication across multiple visits without requiring the actual device to be physically present or complex authentication protocols to be implemented on the device itself, thus improving productivity while maintaining system simplicity.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8756657B2Mobile or user device authentication and tracking
Publication Date: 2014.06.17 PAYPAL INC
  • US8756657B2 patent drawing
  • US8756657B2 patent drawing
  • US8756657B2 patent drawing

AI summary

A system and method, according to one or more embodiments, includes a server computing device configured to communicate with a network-based device via a network; a visitor identification, in which the system generates the visitor identification and the visitor identification corresponds to a piece of information that is unique to the network-based device; a mapping for which the system adds the generated visitor identification to the mapping so that the visitor identification uniquely identifies the network-based device from all other network-based devices in communication with the server computing device; and a database in which the system tracks the visitor identification among a plurality of visitor identifications in the database.