Automated Device Discovery for Authentication Pairing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems are cumbersome, especially on devices with limited input capabilities, and passwords are easily compromised, making traditional authentication methods inefficient and insecure.
Innovation Solution
An automated system for discovering and selecting pairing-eligible devices as a secondary factor for authentication, eliminating the need for manual pairing and password entry by interrogating network resources to present a list of eligible devices for user selection, and completing authentication via a chosen secondary device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual pairing is used to associate a secondary device with a computing device for authentication, then device association can be established, but the authentication process becomes cumbersome and time-consuming
Solution Approach 1:
The system performs automated device discovery and pairing without requiring manual user intervention. The computing device automatically queries network resources, receives lists of pairing-eligible devices, and completes the pairing process autonomously, eliminating the need for users to manually scan QR codes or enter pairing information.
Solution Approach 2:
Pairing-eligible devices pre-register their availability with network resources before the authentication event. When authentication is needed, the computing device simply queries the network resource which already has the list of eligible devices ready, eliminating the need for real-time manual pairing setup.
2Reliability
If password entry is required for authentication, then user identity can be verified, but the process becomes cumbersome on devices without keyboards and passwords become easily compromised
Solution Approach 1:
The system replaces the mechanical/password-based authentication mechanism with a possession-factor mechanism. Instead of requiring users to type passwords on keyboards, the system uses alternative devices (smartphones, tablets, wearables) that can present authentication challenges through their own interfaces, substituting the traditional password entry mechanism entirely.
Solution Approach 2:
A secondary device acts as an intermediary between the user and the authentication system. The secondary device receives authentication challenges from the computing device and presents them to the user through its own interface, then returns the authentication response. This intermediary approach eliminates the need for direct password entry on the computing device.
3Ease of operation
If automated device discovery is implemented, then pairing operation convenience is improved, but device complexity increases due to network resource interrogation
Solution Approach 1:
The authentication system leverages existing network resources (such as wireless network routers or access points) that already perform multiple functions including network management, device registration, and communication. By using these universal network resources for device discovery and pairing, the system avoids adding dedicated complex hardware while still achieving automated pairing capabilities.
Data Source
AI summary
Automated device discovery of pairing-eligible devices for authenticating an unidentified user of a computing device is provided. When the user initiates a login on the computing device on which the user's identity is not known, an automated pairing-eligible device discovery authentication system interrogates a resource (e.g., subnetwork router, calendaring server) for identifying pairing-eligible devices that may be used as a second factor for authentication. A list of the pairing-eligible devices is presented to the user on the computing device. Upon selection of a pairing-eligible device to use as a second factor to verify the user's identity, the user's identity is determined, and a notification is sent to the selected pairing-eligible device for enabling the user to verify his/her identity using a second factor. Upon completion of an authentication challenge on the selected pairing-eligible device, authentication of the user is completed, and a signed token is sent to the computing device.


