Bluetooth Proximity Authentication with Dynamic Assurance Levels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication and authorization schemes provide an all-or-nothing approach, failing to effectively manage varying levels of assurance for user transactions across different services, leading to vulnerabilities in information security, especially with the increasing threat of online fraud.
Innovation Solution
A method and system that utilize a Level of Assurance (LOA) Server to dynamically manage authentication and authorization based on contextual factors, enabling real-time adjustments of assurance levels for transactions by forming proximity-enforced Bluetooth communication links, using biometric information, and contextual identifiers to verify user identities and grant access to services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional all-or-nothing authentication is used, then system simplicity is maintained, but security against online fraud is insufficient
Solution Approach 1:
The authentication system is segmented into multiple independent factors (biometric, contextual, device-based) that can be combined in different ways. The Level of Assurance server acts as a coordinator that selects and validates appropriate factors based on the specific transaction requirements, enabling flexible security without requiring a monolithic complex system.
Solution Approach 2:
The authentication system transitions from static all-or-nothing validation to dynamic, adaptive authentication. The Level of Assurance server dynamically selects which authentication factors to require based on real-time risk assessment, transaction type, and user behavior patterns, allowing the system to adjust security requirements flexibly.
2Reliability
If dynamic Level of Assurance authentication is implemented, then security against online fraud is improved, but authentication process complexity increases
Solution Approach 1:
The system performs self-service authentication by automatically assessing risk and selecting appropriate validation factors without requiring manual user input for each factor. The Level of Assurance server handles the complexity of coordinating multiple authentication methods, presenting users with simplified prompts based on the assessed risk level.
Solution Approach 2:
The authentication process adapts its parameters dynamically based on risk assessment. When low risk is detected, the system uses simpler authentication methods; when high risk is detected, it automatically escalates to more rigorous validation. This parameter change approach maintains ease of operation while improving security.
3Reliability
If multiple authentication factors are required, then authentication security is enhanced, but transaction processing time increases
Solution Approach 1:
The system applies partial authentication action by requiring only the necessary authentication factors based on the specific transaction risk level. Instead of always requiring full multi-factor authentication, the system uses the minimum effective set of factors, improving processing speed while maintaining security where needed.
Solution Approach 2:
The Level of Assurance server continuously monitors authentication attempts and transaction outcomes to refine its risk assessment feedback loop. This feedback mechanism learns from patterns to more accurately predict when full authentication is necessary, reducing unnecessary delays while maintaining security.
Data Source
AI summary
A system and method for authorizing a Client Device requested access, the method comprising: forming a proximity enforced Bluetooth® binded communication link between the Client Device and a Level of Assurance (LOA) Provider; providing a login screen to a user entity at the Client Device from a Relying Party (RP) Services Application; receiving login information from the user entity; obtaining identity of the user entity on the LOA Provider using a biometric information of the user entity; sending the biometric information, a private key and contextual identifiers to an LOA Server; and identifying the user entity at the LOA Server using the biometric information, the private key and the contextual identifiers and the Client Device in determining whether to grant access to the RP Services Application.


