Anchored Device Fingerprinting for Risk-Based MFA Reauthentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-factor authentication (MFA) processes are inconvenient and intrusive due to frequent reauthentication requirements, especially for authorized devices, and Wi-Fi fingerprinting can lead to unnecessary reauthentication due to sensitivity to minor location changes.
Innovation Solution
Implementing a security system that uses a stationary anchor device with stable Wi-Fi fingerprints and Bluetooth proximity to determine if a client device remains within a threshold proximity, thereby reducing unnecessary reauthentication by confirming the device's location through comparison with historical benchmarks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multi-factor authentication is implemented to enhance security, then authentication strength is improved, but user convenience deteriorates due to frequent reauthentication requirements
Solution Approach 1:
The system dynamically adjusts authentication requirements based on device behavior patterns and location context. Authorized devices that maintain consistent behavior patterns and location data are exempt from frequent reauthentication, while suspicious activities trigger enhanced authentication. This dynamic approach resolves the contradiction by adapting security stringency to actual risk levels rather than applying uniform reauthentication rules.
Solution Approach 2:
The patent changes the parameter of authentication frequency from fixed to variable based on multiple factors including device trust score, location consistency, and behavior patterns. By modifying this parameter dynamically, the system maintains strong security for unknown devices while providing convenience for authorized devices, thus resolving the contradiction between authentication strength and user convenience.
2Measurement precision
If Wi-Fi fingerprinting is used to detect location changes, then location monitoring precision is improved, but false reauthentication increases due to sensitivity to minor location changes
Solution Approach 1:
The system performs preliminary actions by establishing baseline location data and device behavior patterns during an initial authorization phase. This preliminary data is stored and used later to determine whether observed location changes are significant or merely variations within the normal range. By preparing reference data in advance, the system avoids false reauthentication while maintaining precise location monitoring.
Solution Approach 2:
The system continuously monitors device location and compares it against established baselines, providing feedback to adjust authentication requirements. When location changes are detected, the system analyzes whether the change exceeds predefined thresholds based on historical data. This feedback mechanism allows precise location monitoring while filtering out false positives through contextual analysis of past behavior patterns.
Data Source
AI summary
This disclosure describes techniques for using an anchored endpoint to enhance MFA authentication of a client device. A method performed at least in part by a security service includes determining a fingerprint of a client device connected to a secure resource. The method also includes determining that the client device is within a threshold proximity of an anchor device. The method also includes detecting a change to the fingerprint of the client device. Based at least in part on the client device staying within the threshold proximity of the anchor device, the method also includes continuing to allow the client device to access the secure resource. Based at least in part on detecting that the client device is no longer within the threshold proximity of the anchor device, the method also includes triggering a reauthentication of the client device.


