Cloud Continuous Multifactor Authentication via Sensor Challenges

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current multifactor authentication methods are inadequate in ensuring continuous and secure user authentication, particularly when the trust score of a user device falls below a certain threshold, as they lack a secure and convenient way to re-authenticate users and are vulnerable to attacks when the device is compromised.

Innovation Solution

A cloud-based continuous multifactor authentication system that utilizes a combination of sensors and a neural network to continuously monitor and re-authenticate users by sending challenges based on trait data, such as biometric and contextual information, to ensure secure access to devices, even when the initial trust score is below a threshold.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional single-factor or two-factor authentication is used, then ease of operation is improved, but reliability deteriorates as attackers increasingly compromise user devices

Engineering Contradiction:
Improveauthentication convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system continuously monitors device trust scores and authentication factors, providing feedback loops that dynamically adjust security measures. Sensors continuously collect trait data and update authentication status, creating a real-time feedback mechanism that maintains security while allowing convenient access for legitimate users.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The authentication system transitions from static single-factor or two-factor authentication to dynamic continuous multifactor authentication. The system adapts authentication requirements based on real-time trust scores, device behavior, and sensor data, making security measures flexible and responsive to changing conditions.

Inventive Principle:
Principle #15Dynamics

2Reliability

If multifactor authentication is implemented, then reliability is improved, but device complexity increases and there is no secure convenient way to re-authenticate when trust score drops

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically monitors trust scores and triggers re-authentication processes without requiring user intervention. When a device's trust score drops below thresholds, the system autonomously initiates challenge-response sequences using sensor data and neural networks to verify authenticity, reducing complexity for users while maintaining high security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary authentication checks continuously in the background using sensors and trait data before actual access is needed. By pre-establishing baseline trust scores and monitoring device behavior proactively, the system prepares authentication credentials and challenges in advance, reducing the complexity of on-demand re-authentication.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If continuous monitoring is implemented to maintain authentication, then reliability is improved, but use of energy increases

Engineering Contradiction:
Improvecontinuous authenticationVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Instead of continuous high-power monitoring, the system uses periodic authentication challenges and trust score updates. Sensors collect trait data at intervals, and the neural network processes challenges periodically rather than continuously, reducing energy consumption while maintaining reliable authentication through strategic sampling and event-triggered updates.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11334658B2Systems and methods for cloud-based continuous multifactor authentication
Publication Date: 2022.05.17 PPIP LLC
  • US11334658B2 patent drawing
  • US11334658B2 patent drawing
  • US11334658B2 patent drawing

AI summary

Disclosed is an apparatus performing a method including: receiving, from an apparatus including a housing arranged to hold a personal communication device used by a user, a notification indicating a first authentication score of the user is below a first pre-determined threshold, providing a challenge to the personal communication device. In some embodiments, the challenge is selected based on one or more sensor data obtained by at least one of the apparatus or the personal communication device. In some embodiments, the method includes calculating a second authentication score based on a response to the challenge, and causing the apparatus, to gate electronic access to the personal communication device based on whether the second authentication score is above a second pre-determined threshold.