User Authentication Using Device Orientation and Proximity Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current user authentication methods in IT environments often send unnecessary authentication requests to users and mobile devices within a detected range, leading to inefficiencies and potential security risks by indiscriminately notifying devices that may not intend to access computer systems.
Innovation Solution
A method and system that authenticates users by calculating the distance and orientation of client devices relative to computer systems, sending notifications only when the device is within a predetermined distance and orientation, utilizing sensors and biometric identifiers to ensure accurate authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If proximity detection is used to identify users within detected range, then user authentication can be initiated, but unnecessary authentication requests are sent to users and mobile devices that have no intention of logging in
Solution Approach 1:
The patent applies local quality by making the authentication notification targeted and specific rather than broadcast to all nearby devices. The system determines whether to send notifications based on local conditions at each device location, specifically checking orientation and intent signals. This resolves the contradiction by sending authentication requests only to devices with relevant local characteristics (correct orientation, login intent) rather than all devices in proximity.
Solution Approach 2:
The patent changes parameters from simple proximity detection to multi-parameter detection including orientation, distance, and intent signals. By adding orientation detection and intent signal monitoring as additional parameters, the system filters out devices that are merely nearby but not actually intending to authenticate. This resolves the contradiction by using parameter changes to distinguish between relevant and irrelevant authentication requests.
2Reliability
If authentication requests are sent to all devices within detected range, then potential users can be identified, but security risks increase by notifying devices that may not intend to access computer systems
Solution Approach 1:
The patent applies preliminary action by checking orientation and intent signals before sending authentication requests. The system performs preliminary verification to determine if a device is actually intending to access the computer system before initiating authentication. This resolves the contradiction by performing preliminary actions that filter out unintended authentication attempts, thereby maintaining reliability while reducing security risks.
Solution Approach 2:
The patent uses feedback mechanisms by monitoring intent signals and orientation data from devices to determine whether to send authentication requests. The system continuously receives feedback from devices about their state and intent, using this feedback to make intelligent decisions about authentication request transmission. This resolves the contradiction by using feedback to distinguish between legitimate authentication needs and potential security threats.
3Ease of operation
If proximity-based authentication notification is sent, then users can be prompted to log in, but false alerts are generated for devices not intending to access the system
Solution Approach 1:
The patent applies partial action by sending authentication requests to only a subset of devices within proximity - specifically those that meet certain criteria like correct orientation and detected intent signals. Rather than notifying all nearby devices (excessive action), the system selectively notifies only those likely to be legitimate users. This resolves the contradiction by using partial action to reduce false alerts while still maintaining ease of operation for legitimate users.
Data Source
AI summary
A method, a system, and a non-transitory computer readable program code are disclosed for authenticating users. The method includes registering, on a processing device, one or more users in an authentication system, each of the one or more users having at least one corresponding client device; receiving, on the processing device, location data from the at least one corresponding client device; receiving, on the processing device, location data from one or more computer systems; calculating, on the processing device, a distance from the one or more computer systems to the at least one corresponding client device; receiving, by the processing device, an orientation or orientations of the at least one corresponding client device; and sending, by the processing device, a notification to the at least one corresponding client device.


