Wearable Security Token for Mobile Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices face security challenges due to the inconvenience of existing authentication methods and the risk of theft, as users often disable security measures or use easily compromised biometrics, and existing protection schemes are not effective against hard-core hackers.

Innovation Solution

A wearable security token device that contains cryptographic keys, separating security management from the mobile device, using challenge-response protocols and asymmetric or symmetric key systems to ensure secure data access, requiring both the device and token to be stolen for unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional authentication methods (passwords, biometrics) are used, then ease of operation is improved, but security reliability deteriorates

Engineering Contradiction:
Improveauthentication convenienceVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system is segmented into two separate components: a mobile device and a wearable security token. The security token contains cryptographic keys and is worn by the user, while the mobile device handles the authentication process. This segmentation allows the system to maintain ease of operation through automatic authentication while significantly improving security reliability by requiring physical possession of the token.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A wearable security token acts as an intermediary between the user and the mobile device authentication system. The token contains cryptographic keys and communicates with the mobile device to verify identity without requiring the user to manually enter passwords or expose biometric data. This intermediary mechanism enhances both convenience and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If encryption keys are stored on the mobile device, then ease of operation is improved, but security reliability deteriorates due to device theft risk

Engineering Contradiction:
Improvedata access convenienceVSAvoidprotection against theft
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The cryptographic keys are extracted from the mobile device and relocated to a separate wearable security token. This extraction ensures that even if the mobile device is stolen, the attacker cannot access encrypted data without the token. The token can be worn on the user's person, making it much harder to steal simultaneously with the device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The security system is divided into two parts: the mobile device stores encrypted data, while the wearable token stores the decryption keys. This segmentation ensures that compromising one component does not automatically compromise the other, significantly improving protection against device theft.

Inventive Principle:
Principle #1Segmentation

3Reliability

If security measures are made more stringent, then security reliability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity protection levelVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The wearable security token performs authentication automatically without requiring user intervention. The token contains the cryptographic keys and can independently communicate with the mobile device to verify identity and decrypt data. This self-service capability maintains high security reliability while preserving ease of operation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10922684B2Mobile device security using wearable security tokens
Publication Date: 2021.02.16 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10922684B2 patent drawing
  • US10922684B2 patent drawing
  • US10922684B2 patent drawing

AI summary

Optimizations are provided for completing a transaction event using authentication information. In particular, a presence of a transaction processing device is initially detected. Then, transaction information is received from the transaction processing device. The transaction information corresponds to a current transaction event. After receiving the information, a communication link is established with an on-body device. This device includes authentication information that is necessary to complete the current transaction event. The authentication information is then received from the on-body device. This information has a time-limited use availability. Finally, the received authentication information is used to complete the current transaction event.