Text Messaging Self-Service Authentication System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems face challenges in securely and efficiently authenticating account access without a physical authentication token, often relying on third parties that introduce security risks and latency.
Innovation Solution
The system employs text messaging-based self-service authentication using mobile device information, allowing users to authenticate directly with the system through a mobile device, and utilizes tiered authentication protocols and temporary machine-readable codes to enhance security and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If third-party systems are used for authentication without physical tokens, then account access can be enabled, but security risks and data breach vulnerabilities increase
Solution Approach 1:
The patent extracts the authentication process from third-party systems and brings it directly into the target system through text messaging. Users receive authentication codes via SMS directly from the system, eliminating the need to share sensitive information with intermediaries and reducing security vulnerabilities associated with third-party handling of authentication data.
Solution Approach 2:
The patent introduces text messaging as a secure intermediary channel between the system and the user for authentication. Instead of relying on third-party systems to handle authentication, the system uses SMS messages as a trusted mediator to deliver authentication codes directly to users' mobile devices, ensuring security while maintaining ease of access.
2Ease of operation
If third-party systems handle authentication data, then account access is enabled, but latency in the authentication process increases
Solution Approach 1:
The patent removes the authentication processing step from external third-party systems and consolidates it within the target system. By generating and sending authentication codes directly through SMS without external intermediation, the system eliminates the latency introduced by third-party processing and data transmission delays.
3Ease of operation
If personal account information is transmitted to third parties for authentication, then account access is enabled, but the risk of data fabrication and illegal use increases
Solution Approach 1:
The patent extracts personal account information from the authentication exchange entirely. Instead of transmitting sensitive personal data to third parties or even storing it in the system, the authentication process relies solely on mobile device identifiers and SMS-delivered codes, eliminating the vulnerability to data fabrication and illegal use while maintaining straightforward account access.
4Reliability
If data encryption is implemented for third-party transmission, then security is improved, but technical complexity and resource consumption increase
Solution Approach 1:
The patent removes the need for complex encryption protocols by eliminating third-party data transmission entirely. Authentication codes are sent directly through the SMS infrastructure, which provides inherent security without requiring additional encryption layers, thereby reducing technical complexity and resource consumption while maintaining security.
Data Source
AI summary
Methods and systems for text messaging-based self-service authentication in absence of a physical authentication token. In some aspects, the system receives, from a mobile device, a first text message indicating a request for account access in absence of the physical authentication token, in which the mobile device is operating on a mobile network and associated with a user digital identifier relating to the mobile network. The system transmits, to the mobile device, a second text message including a link to a webpage for account access in absence of the physical authentication token; determines, based on mobile device information associated with the mobile device and the user digital identifier, whether to authenticate the request; and in response to authenticating the request, provides a temporary machine-readable code associated with the user account. The temporary machine-readable code may allow a third party to access the user account by scanning the temporary machine-readable code.


