Bluetooth Low Energy Proximity Verification for Multi-Factor Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current multi-factor authentication (MFA) systems are vulnerable to attacks such as push fraud and passcode phishing, where attackers can falsify authentication from unauthorized devices or intercept credentials, compromising network security.
Innovation Solution
Implementing a proximity-based MFA method using Bluetooth Low Energy (BLE) signals to verify the co-location of an authentication device and an access device, ensuring that the user is physically close to the device they are authenticating, thereby increasing the trust level and mitigating risks of unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional multi-factor authentication methods are used, then authentication can be performed remotely without location verification, but the system becomes vulnerable to push fraud and passcode phishing attacks
Solution Approach 1:
The patent introduces Bluetooth Low Energy (BLE) technology as an intermediary mechanism between the authentication device and access device. The BLE proximity verification acts as a mediator that confirms physical co-location before allowing authentication, thereby blocking remote attacks like push fraud and passcode phishing while maintaining legitimate authentication flows.
2Reliability
If proximity verification using BLE signals is implemented, then physical co-location can be confirmed to prevent attacks, but the device complexity and energy consumption increase
Solution Approach 1:
The patent replaces complex mechanical or manual proximity verification methods with Bluetooth Low Energy (BLE) electromagnetic signal-based verification. This substitution enables automatic, software-based proximity detection that is less complex than physical presence verification mechanisms while providing reliable co-location confirmation for security purposes.
Solution Approach 2:
The patent leverages the existing BLE capability already present in modern smartphones and devices, making the proximity verification system universally applicable without requiring specialized hardware. This multi-functional approach uses the device's existing wireless communication capabilities for both standard connectivity and proximity verification, reducing overall system complexity.
3Reliability
If proximity verification is required for authentication, then unauthorized remote access is prevented, but user convenience and authentication speed are reduced
Solution Approach 1:
The patent implements automatic proximity verification where the system itself checks BLE signal presence without requiring user action. The authentication flow automatically verifies co-location through BLE signals in the background, eliminating the need for users to manually confirm physical presence or perform additional steps, thus maintaining convenience while enhancing security.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enhances the security of MFA by confirming the physical proximity of the authentication device to the access device, reducing the likelihood of attacks like push fraud and passcode phishing, thereby strengthening network security and user authentication.
Implementation Method 1
co-location of the authentication device and the access device is determined by receiving a communication from an authentication device including the passcode associated with the user account, where the authentication device extracted the passcode from a message broadcast over Bluetooth Low Energy from the access device
Data Source
AI summary
The present technology provides for a proximity authentication technique in response to a detection of a possible attack, degradation in trust level, or as required by a policy associated with a first resource. Methods and systems include receiving an authentication request to authenticate a user account to a first service, where the authentication request is from an access device. A passcode is sent to the access device, where the d passcode is associated with the authentication request. Co-location of the authentication device and the access device is determined by receiving a communication from an authentication device including the passcode associated with the user account, where the authentication device extracted the passcode from a message broadcast over Bluetooth Low Energy from the access device.


