Smartphone Authentication Using External Secure Medium
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for authenticating users on smartphones running Android or Apple iOS to access secure WEB applications are limited, as they typically store keys and digital certificates internally or on µSD cards, restricting secure transactions.
Innovation Solution
A method that uses a smartphone with an internet browser and a mobile authentication application to redirect the user to an authentication server, where a challenge is sent, prompting the user to unlock a secure external device (smart card or USB key) for authentication, calculating a cryptogram, and transmitting it to the server for verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If keys and digital certificates are stored internally on smartphone or on µSD card, then authentication can be performed on smartphone, but secure transactions are restricted and authentication strength is limited
Solution Approach 1:
The patent introduces a secure external medium (smart card or USB key) as an intermediary device that stores cryptographic keys and digital certificates. This external medium acts as a mediator between the user and the authentication system, enabling strong authentication while maintaining versatility across different devices. The secure external medium contains a cryptographic module that performs cryptographic operations without exposing the private key, thus providing both security and adaptability.
Solution Approach 2:
The patent makes the secure external medium universal by enabling it to work with multiple device types (PC, Mac, Smartphone) through standardized communication interfaces. The same smart card or USB key can be used for authentication across different operating systems and devices, eliminating the need for device-specific authentication mechanisms and enhancing both authentication strength and transaction versatility.
2Adaptability or versatility
If multiple key media and digital certificates are used for different devices, then device-specific authentication is enabled, but user management complexity increases
Solution Approach 1:
The patent implements a universal secure external medium that can be used across multiple device types (PC, Mac, Smartphone) with different operating systems. The smart card or USB key contains all necessary cryptographic credentials and can perform authentication operations on any supported device, eliminating the need for users to manage separate key media for each device and significantly reducing management complexity.
3Ease of operation
If cryptographic operations are performed on smartphone, then authentication can be completed on mobile device, but security may be compromised due to smartphone vulnerabilities
Solution Approach 1:
The patent uses a secure external medium as an intermediary that performs all sensitive cryptographic operations outside the smartphone's vulnerable environment. The smart card or USB key contains a protected cryptographic module that generates and stores private keys in a secure element, performing all cryptographic operations internally without exposing sensitive data to the smartphone's potentially insecure software environment.
Solution Approach 2:
The patent segments the authentication system into two distinct parts: a secure external medium that handles sensitive cryptographic operations and key storage, and a smartphone that provides only the user interface and communication channel. This segmentation isolates security-critical functions from the vulnerable smartphone environment while maintaining ease of mobile operation.
Data Source
Figure 1
AI summary
The invention relates to a method for authentication in a secure web application of a user provided with a smartphone previously loaded with an internet browser and a mobile authentication application, said method using a standard internet browser on the smartphone, and a secure external medium such as a chip card in order to calculate a cryptogram that is submitted by the smartphone to an authentication server.