Trusted Session Authentication via Intermediary Device Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face the inconvenience of needing to undergo separate authentication steps on multiple devices to establish a trusted session with a remote computer system, which can be cumbersome and time-consuming.

Innovation Solution

A computer system and method that allows a first computing device to authenticate to an account using a second computing device with an existing trusted relationship, by comparing identifying information such as network details and geolocation to determine correspondence, and then requesting confirmation from the second device before authenticating the first device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If separate authentication steps are required for each device, then security is maintained, but user convenience deteriorates and authentication time increases

Engineering Contradiction:
Improveauthentication convenienceVSAvoidauthentication time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent introduces a trusted device as an intermediary that already has an established trusted session with the remote computer system. Instead of requiring the first device to perform direct authentication, the system uses the second device's existing trusted relationship as a mediator to enable authentication of the first device, thereby reducing authentication time and improving convenience while maintaining security through device trust relationships

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple authentication steps are implemented on each device, then authentication security is improved, but device complexity and user burden increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is segmented into two distinct phases: (1) a first device establishes a trusted session with a remote computer system, and (2) a second device uses that established trusted session to authenticate a first device. This segmentation allows the complex authentication logic to be distributed and simplified, where the second device leverages existing trust rather than performing complete authentication from scratch, reducing overall system complexity while maintaining security

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11632674B2System and method for establishing a trusted session
Publication Date: 2023.04.18 THE TORONTO DOMINION BANK
  • US11632674B2 patent drawing
  • US11632674B2 patent drawing
  • US11632674B2 patent drawing

AI summary

A method for establishing a trusted session between a first computing device and a computer server includes obtaining identifying information for the first computing device and a second computing device. The identifying information includes identifying information corresponding to the networks to which each of the computing devices are directly connected. Based on the identifying information it may be determined that there is sufficient correspondence between the first and second computing devices. If so, an indication is sent to the second computing device requesting confirmation that the first computing device should be authenticated to the account. An indication confirming this may then be received and, responsive thereto, the first computing device is authenticated to the account. Related computer systems and computer-readable media are also disclosed.