Wireless Authentication Code for Token Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Devices without input/output interfaces cannot perform authentication processes, and existing OAuth-based authentication schemes are insecure due to password storage in web cookies, making it difficult for them to authenticate and update tokens periodically.

Innovation Solution

A method and device for transmitting and receiving authentication information in a wireless communication system, where a first device obtains access information from an authentication server, connects with a second device, and registers it with a service providing server, allowing the second device to periodically update its access token without user input.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If OAuth-based authentication scheme is used with ID and password, then user authentication can be performed across multiple applications, but password security is compromised due to storage in web cookies

Engineering Contradiction:
Improveauthentication across applicationsVSAvoidpassword exposure
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the password from the authentication process by introducing a separate authentication code that is displayed to the user rather than transmitted. The authentication code is generated by the authentication server and displayed on the user's device screen, eliminating the need to transmit or store passwords in cookies, thus resolving the security issue while maintaining cross-application authentication capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an authentication code as an intermediary element between the user's credentials and the authentication server. Instead of directly transmitting passwords, the system uses this intermediate authentication code that is visually presented to the user and then transmitted to complete authentication, thereby protecting the original password from exposure

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If authentication device requests user input for ID and password, then authentication can be performed, but devices without input/output interfaces cannot authenticate

Engineering Contradiction:
Improveauthentication processVSAvoiddevice compatibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent enables devices without input/output interfaces to authenticate themselves automatically. The authentication server generates and displays the authentication code on the device's own screen, allowing the device to complete authentication without requiring external user input through buttons or keyboards. The device essentially serves itself by displaying its own authentication code

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The authentication code serves as an intermediary that bridges the gap between devices without input interfaces and the authentication server. Instead of requiring direct user input, the system uses this visual intermediary code that can be displayed on any device screen and transmitted automatically, enabling universal device compatibility

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If access token is used for service authentication, then service access can be controlled, but token needs periodic updating which requires user input

Engineering Contradiction:
Improveservice access controlVSAvoidtoken update process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by having the authentication server automatically generate and provide a long-lived authentication code to the device during initial authentication. This pre-provisioned authentication code enables the device to periodically update its access tokens without requiring real-time user input, as the authentication code is already stored and can be automatically reused for token refresh operations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The device uses the pre-stored authentication code to automatically update its own access tokens without external intervention. The device performs self-service by utilizing its existing authentication credentials to refresh service tokens as needed, eliminating the requirement for user input during periodic token updates while maintaining secure service access control

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10708774B2Method and device for transmitting and receiving authentication information in wireless communication system
Publication Date: 2020.07.07 SAMSUNG ELECTRONICS CO LTD
  • US10708774B2 patent drawing
  • US10708774B2 patent drawing
  • US10708774B2 patent drawing

AI summary

A method for transmitting authentication information of a service provided from a service providing server at a first device in a wireless communication system comprising a plurality of devices includes obtaining, from an authentication server, first access information using an authentication code obtained based on an IDentifier (ID) and a password of an application for using of the service from the authentication server, transmitting, to the service providing server, a service request message comprising the first access information, performing a connection procedure with a second device among the plurality of devices, obtaining from the connected second device, second device information, and after registering the second device to the service providing server based on the second device information, transmitting, to the second device, registration information comprising the authentication code. The authentication code is used to request second access information of the second device to the authentication server.