Multi-Factor Authentication Security Posture Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional remote access systems lack a user-friendly, cost-effective, and transparent enhanced security layer for authentication, making them vulnerable to unauthorized access and breaches, as they rely primarily on username/password authentication without repeated security checks.

Innovation Solution

The system employs an encrypted query and response protocol to evaluate the requesting device's security posture, using cryptographic certificates and device-specific criteria, with repeated reevaluations and rotating questions, ensuring compliance with predefined policies and minimizing risks like certificate theft.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional username/password authentication is used for remote access, then ease of operation is improved, but security reliability deteriorates due to lack of repeated security checks

Engineering Contradiction:
Improveauthentication simplicityVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary security assessments by evaluating device security posture, cryptographic certificates, and compliance with security policies before granting remote access. This preliminary action ensures that only devices meeting security requirements can authenticate, thereby improving security reliability without significantly impacting ease of operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback mechanisms by repeatedly reevaluating the security posture of authenticated devices during the remote access session. Rotating security questions and ongoing compliance checks provide feedback loops that maintain security reliability while allowing legitimate users to continue operations with minimal disruption.

Inventive Principle:
Principle #23Feedback

2Reliability

If enhanced security checks with cryptographic certificates and device evaluation are implemented, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary authentication service that manages the complexity of cryptographic certificate verification, device security posture evaluation, and policy compliance checking. This intermediary handles the complex security checks on behalf of the remote access system, improving security reliability while shielding the complexity from end users and simplifying the overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If repeated security reevaluations with rotating questions are performed, then security reliability is improved, but loss of time increases due to multiple authentication checks

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements periodic security reevaluations at strategically determined intervals during the remote access session, rather than requiring continuous authentication checks. Rotating security questions are presented periodically based on risk assessments and session duration, maintaining security reliability while minimizing the time loss associated with repeated authentication checks.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10333930B2System and method for transparent multi-factor authentication and security posture checking
Publication Date: 2019.06.25 INNOVATEPRO MANAGEMENT USA LLC
  • US10333930B2 patent drawing
  • US10333930B2 patent drawing
  • US10333930B2 patent drawing

AI summary

A method for creating a secure connection between a remote client computing device and an enterprise asset platform includes a server receiving from a client computing device (CCD) a request being either a registration request or to access the asset platform, including a CCD unique identifier, determining if the CCD is previously blocked from accessing the asset platform, if so then terminating the method. If the request is a registration request, then generating a disambiguation query in accordance with predefined policy, receiving a response to the disambiguation inquiry from the CCD, verifying the contents of the disambiguation query response in relation to a predefined criteria. If the disambiguation query response does meet the predefined policy, associating the CCD to the predefined policy. A system configured to implement the method and a non-transitory computer-readable medium containing instructions for a processor to perform the method are also disclosed.