Wearable Security Token for Mobile Device Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices face security challenges due to the inconvenience of existing authentication methods and the risk of theft, as users often disable security measures or use easily compromised biometrics, and existing protection schemes are not effective against hard-core hackers.
Innovation Solution
A wearable security token device that contains cryptographic keys, separating security management from the mobile device, using challenge-response protocols and asymmetric or symmetric key systems to ensure secure data access, requiring both the device and token to be stolen for unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional authentication methods (passwords, biometrics) are used, then ease of operation is improved, but security reliability deteriorates
Solution Approach 1:
The authentication system is segmented into two separate components: a mobile device and a wearable security token. The security token contains cryptographic keys and is worn by the user, while the mobile device handles the authentication process. This segmentation allows the system to maintain ease of operation through automatic authentication while significantly improving security reliability by requiring physical possession of the token.
Solution Approach 2:
A wearable security token acts as an intermediary between the user and the mobile device authentication system. The token contains cryptographic keys and communicates with the mobile device to verify identity without requiring the user to manually enter passwords or expose biometric data. This intermediary mechanism enhances both convenience and security.
2Ease of operation
If encryption keys are stored on the mobile device, then ease of operation is improved, but security reliability deteriorates due to device theft risk
Solution Approach 1:
The cryptographic keys are extracted from the mobile device and relocated to a separate wearable security token. This extraction ensures that even if the mobile device is stolen, the attacker cannot access encrypted data without the token. The token can be worn on the user's person, making it much harder to steal simultaneously with the device.
Solution Approach 2:
The security system is divided into two parts: the mobile device stores encrypted data, while the wearable token stores the decryption keys. This segmentation ensures that compromising one component does not automatically compromise the other, significantly improving protection against device theft.
3Reliability
If security measures are made more stringent, then security reliability is improved, but ease of operation deteriorates
Solution Approach 1:
The wearable security token performs authentication automatically without requiring user intervention. The token contains the cryptographic keys and can independently communicate with the mobile device to verify identity and decrypt data. This self-service capability maintains high security reliability while preserving ease of operation.
Data Source
AI summary
Optimizations are provided for completing a transaction event using authentication information. In particular, a presence of a transaction processing device is initially detected. Then, transaction information is received from the transaction processing device. The transaction information corresponds to a current transaction event. After receiving the information, a communication link is established with an on-body device. This device includes authentication information that is necessary to complete the current transaction event. The authentication information is then received from the on-body device. This information has a time-limited use availability. Finally, the received authentication information is used to complete the current transaction event.


