Temporary Password Authentication Across Four Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems for mobile devices, particularly in financial transactions and access to private properties, are not entirely secure due to risks of password theft and hacking, especially during online transmissions and biometric data manipulation.

Innovation Solution

A method involving at least four electronic devices - a smartphone, a secondary 'smart device', remote networked servers, and a POS or electronic lock - uses a unique temporary personal password that changes frequently, eliminating the need for PINs or QR codes, and is stored on both the device and server, ensuring secure authentication through a decentralized control chain.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication systems (PINs, QR codes, biometric data) are used for mobile device authentication, then the authentication process is relatively simple to implement, but the security level is insufficient due to risks of password theft and hacking

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is divided into multiple independent components: a primary mobile device, a secondary smart device (accessory), and a remote server. Each component stores and processes authentication credentials independently, creating a segmented architecture where compromise of one component does not necessarily compromise the entire system. The authentication credential is split between the mobile device and the secondary smart device, requiring both to be present for successful authentication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secondary smart device (accessory item) is introduced as an intermediary element between the mobile device and the authentication target (POS terminal, electronic lock, etc.). This intermediary carries and transmits the authentication credential, acting as a secure mediator that prevents direct exposure of sensitive data on the primary mobile device. The intermediary device requires physical possession and proximity to facilitate authentication, adding a layer of security through physical control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If additional authentication codes or PINs are required for mobile payments and sensitive activities, then the security level improves, but the ease of operation deteriorates due to multiple authentication steps

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Multiple authentication factors (possession of mobile device, possession of secondary smart device, and proximity) are merged into a single unified authentication process. The authentication credential is combined within the secondary smart device, which itself is physically attached to or in close proximity with the mobile device. This merging allows the system to achieve high security through multiple factors while maintaining operational simplicity for the user, as the combined credential is transmitted automatically when the devices are in the required proximity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system enables self-service authentication where the authentication credential is automatically generated, stored, and transmitted without requiring user intervention in the technical process. The secondary smart device automatically manages the authentication credential and initiates transmission when triggered by the presence of the mobile device or a authentication request, eliminating the need for users to manually enter codes or manage multiple authentication steps.

Inventive Principle:
Principle #25Self-service

3Loss of time

If biometric data and sensitive information are stored on the mobile device for authentication, then the authentication process becomes faster, but the vulnerability to hacking and data theft increases

Engineering Contradiction:
Improveauthentication timeVSAvoidvulnerability to hacking
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

The authentication credential (biometric data or sensitive information) is extracted from the primary mobile device and transferred to a separate secondary smart device (accessory). This extraction removes the vulnerable data from the device that is constantly connected to networks and applications, placing it instead in a dedicated security device that has limited functionality and reduced attack surface. The credential exists only in this separated form, not on the primary mobile device, thereby eliminating the risk of digital attacks on that device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication credential in the secondary smart device is designed to be ephemeral and non-reusable. After each successful authentication, the credential becomes invalid and cannot be reused, similar to a disposable security token. This approach prioritizes security over reusability, ensuring that even if the credential is compromised during transmission or storage, it cannot be exploited for repeated attacks. The credential is essentially a single-use security element that provides fast authentication while minimizing long-term security risks.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentEP3752936B1Identity authentication process/method by sending and exchanging a temporary personal password among at least four electronic devices for recharges, payments, accesses and/or ids of the owner of a mobile device, such as a smartphone
Publication Date: 2021.12.29 ENG TEAM
  • EP3752936B1 patent drawingFigure 1
  • EP3752936B1 patent drawingFigure 2
  • EP3752936B1 patent drawingFigure 3

AI summary

A method for obtaining a high security system for a strong authentication of the identity of the user or owner of a smartphone, tablet or other mobile electronic device (10), to which a secondary element or accessory item (20), such as a smart device, is coupled; the system is used for obtaining a prior authentication so as to carry out sensitive activities, such as a recharging of a financial instrument, mobile or remote payments, accesses to private properties or places or things with prior authorization of access and/or identification of the user or owner of the mobile electronic device (10) for bureaucratic formalities, and employs a software application (APP), which provides for sending and exchanging a temporary personal password of the user, usable only once, among at least four electronic devices.