Portable Authenticator Proximity Locking for Continuous User Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems fail to provide continuous, automatic, and unobtrusive authentication, allowing unauthorized access when authorized users leave their devices unattended, leading to potential security breaches.

Innovation Solution

Implementing a geolocation-based authentication system using wearable or portable authenticators in conjunction with distributed location detection devices that continuously monitor user proximity to workstations, employing Bluetooth, NFC, or RFID protocols to ensure real-time secondary authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the operating system locks the computer after a longer period of inactivity (e.g., 15 minutes), then user productivity is improved and frequent logins are reduced, but security is worsened because unauthorized users can access the computer before the lock timeout occurs

Engineering Contradiction:
Improveuser productivityVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements continuous geolocation monitoring of the user via wearable authenticators, which continuously tracks user position and automatically triggers lockout when the user moves away from the workstation. This continuous monitoring eliminates the security gap that exists during the inactive period before OS lockout, maintaining security without requiring frequent manual logins.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The patent replaces the mechanical/time-based OS lockout mechanism with an electronic geolocation-based authentication system. Instead of relying on the operating system's inactivity timer, the system uses wearable authenticators with GPS/geolocation capabilities to continuously monitor user proximity and trigger automatic lockout based on physical movement, providing real-time security response.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If the operating system locks the computer after a shorter period of inactivity (e.g., 1 minute), then security is improved, but user productivity deteriorates due to frequent and recurring logins

Engineering Contradiction:
ImprovesecurityVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The continuous geolocation monitoring maintains constant security oversight without requiring periodic lockouts. The system only triggers authentication when the user actually moves away from the workstation, eliminating unnecessary frequent logins while maintaining tight security control throughout the work session.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system automatically detects user movement and triggers lockout without requiring user intervention or awareness. The wearable authenticator continuously monitors position and the system self-manages the authentication state, locking only when the user physically moves away, thus maintaining security without frustrating the user with unnecessary logins.

Inventive Principle:
Principle #25Self-service

3Reliability

If continuous real-time geolocation monitoring is implemented, then security is improved by preventing unauthorized access, but device complexity increases due to multiple location detection devices and wearable authenticators

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The wearable authenticator serves multiple functions: it acts as the user's login credential, continuously tracks geolocation, and triggers authentication events. This multi-functional device eliminates the need for separate tracking hardware and simplifies the system architecture by consolidating authentication and monitoring capabilities into a single portable device that users already carry.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses existing wireless communication infrastructure (Wi-Fi, Bluetooth, cellular networks) as intermediaries to transmit geolocation data from wearable authenticators to the authentication system. This approach avoids the need for dedicated tracking infrastructure and leverages already-deployed communication networks, reducing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If geolocation-based continuous authentication is implemented, then security is improved, but loss of time occurs due to initial setup and configuration

Engineering Contradiction:
ImprovesecurityVSAvoidsetup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary geolocation configuration during the initial login process, where users simply enable location services on their mobile devices. The wearable authenticator is pre-paired with the user's account, and the system pre-configures monitoring parameters. This preliminary setup occurs once during onboarding, after which the system operates automatically without requiring additional user time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12526274B2Geolocated portable authenticator for transparent and enhanced information-security authentication of users
Publication Date: 2026.01.13 BANK OF AMERICA CORP
  • US12526274B2 patent drawing
  • US12526274B2 patent drawing
  • US12526274B2 patent drawing

AI summary

An information-security process for enhanced user authentication is disclosed. In addition to username, password, dual-factor and/or other security, an authenticator is worn or carried on the person of a user. The authenticator can be detected to be within local range of a workstation and/or geolocated. If the authenticator corresponds to the user and the user's security information, and if the authenticator is in the correct range or location, access to the workstation can be authorized. Otherwise, it is rejected. Access can also be terminated automatically if the authenticator leaves the security range around the workstation or if a different user's authenticator enters the security range. Positional or range information can be determined by NFC, Bluetooth, BLE, RFID, Wi-Fi, triangulation, time-of-flight protocols/components distributed throughout work area(s) and/or embedded in workstation(s). Cooperative components working therewith are in the authenticator.