Text Messaging Authentication Using Mobile Device Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems face challenges in securely and efficiently authenticating account access without a physical authentication token, often relying on third parties that introduce security risks and latency.
Innovation Solution
The system employs text messaging-based self-service authentication using mobile device information as credentials, allowing users to directly communicate with the system, and selects appropriate authentication protocols based on mobile device data, using temporary machine-readable codes as access tokens.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If third-party systems are used for authentication without physical tokens, then account access can be granted, but security risks increase due to potential data breaches and unauthorized access
Solution Approach 1:
The patent introduces an intermediary authentication system that mediates between the user and the third-party system. Instead of allowing direct access to sensitive account information, the system uses an intermediate authentication mechanism (biometric data, device identifiers, and secure tokens) to verify user identity without exposing personal information to third parties, thus maintaining security while enabling authentication
Solution Approach 2:
The patent creates a copy or representation of the authentication process that does not require sharing actual sensitive data. The system generates authentication tokens and uses device identifiers as proxies for user identity, allowing third-party systems to verify authentication status without accessing or storing actual personal information, thereby reducing security risks
2Reliability
If data is encrypted during transmission to and from third-party systems, then security is improved, but technical complexity and resource consumption increase
Solution Approach 1:
The patent replaces complex cryptographic mechanisms with simpler authentication methods. Instead of requiring full data encryption pipelines, the system uses authentication tokens, device identifiers, and biometric verification that require minimal encryption overhead. The authentication proof is transmitted in a simplified format that reduces both technical complexity and resource consumption while maintaining security
3Ease of operation
If third-party systems handle authentication, then account access is enabled, but latency is introduced affecting transaction performance
Solution Approach 1:
The patent performs authentication verification in advance and stores the authentication result as a valid token on the user's device. When the user needs to access a third-party system, the pre-validated token is used directly without requiring real-time verification with the authentication server, significantly reducing latency. The preliminary authentication action eliminates repeated communication delays during actual transactions
4Ease of operation
If personal account and identification information is provided to third parties, then authentication can proceed, but the risk of information fabrication and illegal use increases
Solution Approach 1:
The patent extracts only the essential authentication elements (biometric data, device identifiers) needed for verification while leaving sensitive personal information (account numbers, identification documents) on the user's device or in secure system storage. The third-party system receives only authentication proofs, not the actual personal information, thereby eliminating the risk of information fabrication and illegal use while maintaining authentication capability
Data Source
AI summary
Methods and systems for managing text messaging-based authentication in absence of a physical authentication token. In some embodiments, the system receives, from a mobile device, a first text message, in which the mobile device is operating on a mobile network and associated with a user digital identifier relating to the mobile network, and the first text message indicates a request for access in absence of the physical authentication token. The system performs an account search based on the user digital identifier. In response to locating a user account associated with the user digital identifier, the system performs an assessment based on mobile device information relating to the mobile network and associated with the user digital identifier; selects, from a plurality of candidate authentication protocols, an authentication protocol based on the assessment; and manages, based on the authentication protocol, the request for access in absence of the physical authentication token.


