Service Login Management via Trusted Device Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges with managing multiple login credentials for various websites and services, leading to forgotten usernames and passwords, and lack of protection against account hacking and seamless access across devices.
Innovation Solution
A system where a first device, such as a smartphone, is registered to authenticate users for accessing services on a second device, like a smart television, without requiring password entry, using a service login management component that maintains trust levels and facilitates non-credential logins based on authorization from the first device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users use the same username and password for multiple services, then ease of operation is improved, but security deteriorates due to increased risk of account hacking
Solution Approach 1:
The patent introduces a third-party authentication service as an intermediary between the user and multiple services. Instead of users directly managing credentials across services, the authentication service acts as a mediator that handles credential verification and device authorization, eliminating the need for users to reuse passwords while maintaining convenient access.
Solution Approach 2:
The authentication system is segmented into separate components: a trusted authentication service, device authorization mechanisms, and service-specific login interfaces. This segmentation allows secure credential management at the service level while maintaining user convenience through device-level authorization, separating security functions from user interaction points.
2Object-affected harmful factors
If users do not use the same username and password for multiple services, then security is improved, but ease of operation deteriorates due to forgotten credentials and locked-out accounts
Solution Approach 1:
The system provides self-service functionality where authenticated users automatically gain access to services without manual credential entry. The authentication service maintains authorization records and automatically validates device credentials, eliminating the need for users to remember or re-enter passwords across different services while maintaining security.
Solution Approach 2:
Device authorization is performed in advance before service access is needed. The authentication service pre-establishes trust relationships between users and their devices, storing authorization records that enable automatic login. This preliminary authorization action eliminates the need for users to remember credentials or face locked-out situations.
3Object-affected harmful factors
If traditional login methods are used on all devices, then security is maintained, but device complexity increases due to need for multiple credential management systems
Solution Approach 1:
The authentication service provides universal functionality across multiple devices and services through a single unified system. Instead of requiring device-specific credential management mechanisms, the patent implements a universal authentication protocol that works consistently across smartphones, tablets, and computers, reducing overall system complexity while maintaining security.
4Ease of operation
If seamless access across devices is implemented, then ease of operation is improved, but reliability deteriorates due to potential unauthorized access
Solution Approach 1:
The system implements continuous feedback loops where the authentication service monitors device authorization status, tracks login attempts, and validates credentials in real-time. This feedback mechanism enables seamless access by automatically verifying device trustworthiness before allowing login, maintaining both convenience and security through continuous validation rather than static credential storage.
Data Source
AI summary
As provided herein, a first device may be registered as authorized to authenticate a user login into a service from a second device (e.g., a smart phone may be used to log the user into a webmail service on a computer without the user having to enter a password through the computer). Responsive to the user attempting to access the service through the second device, a login interface may be displayed on the first device. The user may confirm or deny that the user wants to log into the service on the second device, thus allowing the user to seamlessly log into the service on the second device (e.g., without entering a password) while mitigating unauthorized logins into the service from unknown devices. Further, the user may use the first device to delegate the authority to authenticate the user login into the service to one or more other devices.


