Anchored Device Fingerprinting for Risk-Based MFA Reauthentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-factor authentication (MFA) processes are inconvenient and intrusive due to frequent reauthentication requirements, especially for authorized devices, and Wi-Fi fingerprinting can lead to unnecessary reauthentication due to sensitivity to minor location changes.

Innovation Solution

Implementing a security system that uses a stationary anchor device with stable Wi-Fi fingerprints and Bluetooth proximity to determine if a client device remains within a threshold proximity, thereby reducing unnecessary reauthentication by confirming the device's location through comparison with historical benchmarks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-factor authentication is implemented to enhance security, then authentication strength is improved, but user convenience deteriorates due to frequent reauthentication requirements

Engineering Contradiction:
Improveauthentication strengthVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts authentication requirements based on device behavior patterns and location context. Authorized devices that maintain consistent behavior patterns and location data are exempt from frequent reauthentication, while suspicious activities trigger enhanced authentication. This dynamic approach resolves the contradiction by adapting security stringency to actual risk levels rather than applying uniform reauthentication rules.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of authentication frequency from fixed to variable based on multiple factors including device trust score, location consistency, and behavior patterns. By modifying this parameter dynamically, the system maintains strong security for unknown devices while providing convenience for authorized devices, thus resolving the contradiction between authentication strength and user convenience.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If Wi-Fi fingerprinting is used to detect location changes, then location monitoring precision is improved, but false reauthentication increases due to sensitivity to minor location changes

Engineering Contradiction:
Improvelocation monitoring precisionVSAvoidfalse reauthentication
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by establishing baseline location data and device behavior patterns during an initial authorization phase. This preliminary data is stored and used later to determine whether observed location changes are significant or merely variations within the normal range. By preparing reference data in advance, the system avoids false reauthentication while maintaining precise location monitoring.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors device location and compares it against established baselines, providing feedback to adjust authentication requirements. When location changes are detected, the system analyzes whether the change exceeds predefined thresholds based on historical data. This feedback mechanism allows precise location monitoring while filtering out false positives through contextual analysis of past behavior patterns.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250392911A1Anchored device fingerprinting for risk-based authentication
Publication Date: 2025.12.25 CISCO TECHNOLOGY INC
  • US20250392911A1 patent drawing
  • US20250392911A1 patent drawing
  • US20250392911A1 patent drawing

AI summary

This disclosure describes techniques for using an anchored endpoint to enhance MFA authentication of a client device. A method performed at least in part by a security service includes determining a fingerprint of a client device connected to a secure resource. The method also includes determining that the client device is within a threshold proximity of an anchor device. The method also includes detecting a change to the fingerprint of the client device. Based at least in part on the client device staying within the threshold proximity of the anchor device, the method also includes continuing to allow the client device to access the secure resource. Based at least in part on detecting that the client device is no longer within the threshold proximity of the anchor device, the method also includes triggering a reauthentication of the client device.