Context-Aware Authentication Mechanism for Secure Device Unlocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Biometric authentication mechanisms in portable computing devices can be compromised without user knowledge or permission, leading to unauthorized access and potential harm, as they can be unlocked using stolen or coerced biometric data.

Innovation Solution

A security agent on the client device selectively enables or disables authentication mechanisms based on user-defined rules related to the device's operating characteristics, such as location or time, to ensure secure unlocking.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If biometric authentication mechanisms are made easily accessible for quick unlocking, then ease of operation is improved, but security reliability deteriorates due to potential unauthorized access

Engineering Contradiction:
Improveease of unlockingVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication mechanism dynamically adjusts its behavior based on contextual factors. The system evaluates multiple conditions (location, time, device state) and selectively enables or disables specific authentication methods accordingly. This dynamic adaptation allows the system to maintain ease of operation under trusted conditions while enhancing security reliability when risks are detected.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes operational parameters of authentication mechanisms based on contextual rules. By modifying which authentication methods are enabled, disabled, or prioritized based on factors like location, time of day, and device state, the system optimizes the balance between ease of operation and security reliability under different conditions.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple authentication mechanisms are always enabled for comprehensive security, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into multiple independent mechanisms (biometric, PIN, pattern, etc.), each with its own enable/disable control. The security agent selectively activates only the necessary segments based on contextual conditions, reducing the effective complexity of the system while maintaining comprehensive security capabilities when needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different authentication mechanisms have different levels of activation based on local contextual conditions. The system applies quality differentiation by enabling more robust authentication methods only when specific conditions are met (e.g., location restrictions, time-based rules), thereby reducing overall system complexity while maintaining high security reliability when required.

Inventive Principle:
Principle #3Local quality

3Reliability

If user-defined rules are implemented to control authentication access, then security reliability is improved, but ease of operation deteriorates due to additional configuration requirements

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidease of unlocking
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system provides self-service functionality by automatically evaluating contextual conditions and applying appropriate authentication rules without requiring manual user intervention for each decision. The security agent autonomously makes determination about which authentication methods to enable based on pre-configured rules and current device state, maintaining ease of operation while enhancing security reliability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11755704B2Facilitating secure unlocking of a computing device
Publication Date: 2023.09.12 FORTINET INC
  • US11755704B2 patent drawing
  • US11755704B2 patent drawing
  • US11755704B2 patent drawing

AI summary

Systems and methods for facilitating secure unlocking of a computing device based on user-defined rules are provided. According to one embodiment, a request to unlock a client device is received by a security agent running on the client device. Responsive to the request, information regarding a set of operating characteristics of the client device is obtained by the security agent. One or more authentication mechanisms of multiple authentication mechanisms available on the client device are selectively enabled or disabled by the security agent based on the information regarding the set of operating characteristics and a set of user-defined rules.