A more modular multi-factor authentication system with a maximum of 3 to 4 or more factors and live verification.
A flexible, offline-capable multi-factor authentication system addresses vulnerabilities in existing systems by allowing users to select multiple factors for real-time verification and immediate blocking of unauthorized access, with optional cloud auditing.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Utility models
- Current Assignee / Owner
- HOGL PETER
- Filing Date
- 2026-04-13
- Publication Date
- 2026-07-09
AI Technical Summary
Existing authentication systems are vulnerable to single-factor authentication, especially in offline environments, and lack a universal, modular multi-factor system that verifies at least three to four factors in real time and uniquely identifies users.
A secure, flexible authentication system that allows users to select at least 3 to 4 independent factors, verifies them in real time, blocks unauthorized users, and operates offline, with options for cloud access and auditing.
Provides secure, flexible, and offline-capable multi-factor authentication that instantly identifies users and blocks unauthorized access, with optional cloud auditing.
Abstract
Description
Technical field: The invention relates to systems for the secure authentication and authorization of users, in particular for ATMs, autonomous vehicles, critical infrastructure, military systems, industrial plants and IT systems. Background of the invention: Existing authentication systems rely on either single factors such as NFC cards, fingerprints, or facial recognition. These systems are either offline—local, but only vulnerable to single-factor authentication—or online-dependent, which is problematic in the event of network outages or in critical infrastructure. To date, no universal, modular multi-factor system has been proposed that verifies at least three to four factors in real time, is flexibly selectable, and simultaneously uniquely identifies the owner. Purpose of the invention: Providing a secure, flexible authentication system that uses at least 3 to 4 independent factors, instantly identifies owners, automatically blocks unauthorized users, is offline-capable, optionally expandable, and modular – the user chooses their own factors. Detailed description of the invention: 1. Factor selection and minimum requirements The system offers a selection of the following factors: - NFC - card / physical token - fingerprint on card / token - facial recognition (Face ID) - voice - iris / eye - ear shape, nose shape, hand vein pattern or other biometric features The user selects at least 3 to 4 factors. The system does not allow authentication if the minimum number is not met. The user is clearly informed of security risks if fewer than the minimum number is selected. 2. Live - Check / No - Save: All factors are checked live with each access; biometric data is not permanently stored (maximum data protection). Optimal hybrid mode allows storage in less critical applications. 3. Access logic: Owners are immediately identified if all selected factors are correct. Unauthorized users are immediately blocked as soon as one factor fails. Access is denied if not all factors are correctly verified. 4. Offline capability: The system operates completely offline; no internet, GPS, or cloud connection is required. Cloud access is available as an option for auditing, logging, or updates. 5. Areas of application: ATMs / Banks, Autonomous Driving, PC / Server / Cloud Access, Critical Infrastructure, Military Systems, Industry / Robotics / IoT. 6. Auditing (optional): Every authentication attempt can be logged, visible only to authorized users.
Claims
A multi-factor authentication system consisting of: - at least 3 selectable authentication factors from NFC card, fingerprint, facial recognition, voice, iris, ear shape, nose shape, or other biometric characteristics; - live verification where each factor is checked with every access; - logic that instantly identifies the owner and blocks unauthorized users with each failed factor; - offline functionality that does not require an internet, GPS, or cloud connection. The system according to claim 1, wherein the user selects his own factors, provided that at least 3 factors must be active. The system according to claim 1 or 2, wherein the biometric data is not permanently stored, but is checked live on each access. The system according to one of the preceding claims, wherein access is immediately terminated as soon as a factor is not correctly verified, without unauthorized user gaining access. The system according to one of the preceding claims, fully offline-capable, with optional integration of cloud or network for logging, updates or remote access. The system according to any of the preceding claims for use in ATMs, vehicles, critical infrastructure, military systems, industrial plants, robotics or IT systems. An authentication system according to any of the preceding claims, wherein a physical card serves as a security medium and comprises at least the following security mechanisms: • Fingerprint sensor for authenticating the owner, • Cryptographic, unique ID that is verified on each authentication attempt, • And optionally a mechanical or electrical sensor that functions correctly only with the original card, wherein the card is used in combination with other factors of the multi-factor system to virtually eliminate access by unauthorized persons. An authentication system according to any of the preceding claims, wherein the ATM is equipped such that cash is not stored directly in the dispensing slot, but is provided via an underground or connected vault area (e.g., bank basement), wherein: • Access is only possible after successful multi-factor authentication. • Unauthorized manipulation or blocking of the ATM does not allow direct access to the cash. • And the cash supply is mechanically or electronically controlled so that the cash is only transported upwards or from the side during authorized withdrawals. An authentication system according to any of the preceding claims, wherein the ATM has a recess in a wall that does not directly access the cash container or transport system behind it, such that: • The cash is transported laterally, from above or below, or laterally to the center of the dispensing slot. • Unauthorized access through the recess is practically impossible. • The front of the ATM does not allow direct access to the cash in the event of an explosion or destruction. • And the cash container or transport mechanism is optionally advantageously provided with armored casing. • The system is used in combination with the other factors of the multi-factor authentication system to further prevent access by unauthorized persons.