Adaptive Authentication Matrix for Mobile Device Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile device authentication methods are inadequate in providing a tailored security approach for various services on sophisticated mobile devices, often relying on a single 'all or nothing' authentication parameter, which fails to match the evolving sophistication of mobile devices and the varying importance of data services.

Innovation Solution

A system and method that utilize a matrix of authentication parameters to tailor access control for different applications on a mobile device, allowing for multiple authentication procedures to be applied based on the importance and sensitivity of the data, with periodic polling to ensure continued validity and revoke access as necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single authentication parameter is used for all applications, then the authentication process is simple and easy to operate, but the security level is insufficient for sophisticated mobile devices with varying data importance

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidsecurity level
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system is segmented into multiple independent authentication parameters (e.g., password, biometric data, device location, time of access) that can be individually selected and combined. Each application or data type can be assigned its own authentication parameter(s), allowing simple authentication for low-security applications while implementing stronger authentication for high-security data, thus resolving the contradiction between operational simplicity and security reliability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple authentication parameters are used for each application, then the security level is improved, but the authentication process becomes cumbersome and complex

Engineering Contradiction:
Improvesecurity levelVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Different authentication parameter requirements are applied locally to different applications or data types based on their security needs. High-security applications require multiple authentication parameters, while low-security applications require only simple authentication. This localized approach ensures that users only encounter complex authentication processes when necessary, resolving the contradiction between security requirements and operational ease.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If authentication procedures are tailored to individual services, then the adaptability and security matching is improved, but the device complexity and system overhead increase

Engineering Contradiction:
Improveauthentication tailoring capabilityVSAvoidsystem overhead
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication system is designed as a universal framework that can handle multiple authentication parameters and combinations through a single centralized authentication manager. This multi-functional approach allows the system to tailor authentication procedures to individual services without requiring separate authentication mechanisms for each application, thereby achieving adaptability while minimizing system overhead and complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7860486B2Key revocation in a mobile device
Publication Date: 2010.12.28 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US7860486B2 patent drawing
  • US7860486B2 patent drawing
  • US7860486B2 patent drawing

AI summary

A system for revoking access to a mobile device comprises a mobile device providing a plurality of applications and an agent providing a plurality of revocation procedures for revoking access by the mobile device to the plurality of applications running on the mobile device. Access to a first application is revoked by the agent using a first revocation procedure, and access to a second application is revoked by the agent using a second revocation procedure.