Anchored Wi-Fi Fingerprinting to Reduce MFA Reauthentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-factor authentication (MFA) processes, particularly those involving Wi-Fi fingerprinting for location verification, often require frequent reauthentication due to sensitivity to minor location changes, leading to user inconvenience and unnecessary authentication requests.
Innovation Solution
Implementing a threshold proximity-based authentication method using a stationary anchor device with stable Wi-Fi fingerprints, verified through Bluetooth pairing, to determine if a client device remains within a trusted location before requiring reauthentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Wi-Fi fingerprinting is used for location verification in MFA, then security is enhanced, but frequent reauthentication is triggered due to sensitivity to minor location changes
Solution Approach 1:
The patent applies local quality by introducing anchor devices at specific locations (workplace, home, cafe) that serve as reference points for Wi-Fi fingerprinting. Each anchor device maintains a stable Wi-Fi fingerprint profile for its local environment, allowing the system to distinguish between minor client device movements and actual location changes. This localized approach resolves the contradiction by enhancing security through location verification while preventing unnecessary reauthentication when clients move within acceptable ranges of anchor devices.
Solution Approach 2:
The patent uses anchor devices as intermediaries between the client device and the authentication system. The anchor device's stable Wi-Fi fingerprint acts as a mediator that absorbs variations caused by client device movement. When a client device connects, the system compares its observed Wi-Fi fingerprint against the anchor device's stored profile, allowing for tolerance of minor changes while still detecting genuine location changes, thus balancing security and user convenience.
2Reliability
If Wi-Fi fingerprinting sensitivity is increased to detect location changes, then security is improved, but unnecessary reauthentication requests increase
Solution Approach 1:
The patent applies parameter changes by modifying the Wi-Fi fingerprint comparison parameters through the introduction of anchor devices. Instead of directly comparing client device fingerprints with strict thresholds, the system uses anchor device profiles as reference points with built-in tolerance parameters. This allows the system to maintain high security by detecting genuine location changes while avoiding unnecessary reauthentication for minor variations, thus improving authentication efficiency without compromising security.
3Reliability
If MFA is implemented with strict location verification, then security is enhanced, but reauthentication frequency increases causing user frustration
Solution Approach 1:
The patent applies preliminary action by pre-establishing anchor devices at known locations before client devices need authentication. These anchor devices pre-compute and store their Wi-Fi fingerprint profiles, creating a ready-reference framework. When client devices connect, the authentication process leverages these pre-prepared profiles to quickly determine location validity, reducing the time required for reauthentication while maintaining strict security verification.
Data Source
AI summary
This disclosure describes techniques for using an anchored endpoint to enhance MFA authentication of a client device. A method performed at least in part by a security service includes authenticating of a client device connecting to a secure resource. The method also includes determining a first Wi-Fi fingerprint of the client device, determining that the client device is within a threshold proximity to an anchor device, and determining a second Wi-Fi fingerprint of the anchor device. The method also includes detecting a change to the first Wi-Fi fingerprint of the client device and determining that the second Wi-Fi fingerprint of the anchor device has not changed. The method also includes determining whether the client device is within the threshold proximity of the anchor device, if it is, access to the secured resource continues to be allowed, if it is not, a reauthentication of the client device is triggered.


