Continuous Multi-Factor Authentication for Secure Session Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods are vulnerable to compromise, fail to ensure user identity with high certainty, expose personal information, and do not maintain secure sessions, as they are focused on initial session initiation rather than continuous verification.
Innovation Solution
A continuous multi-factor authentication system that uses a trusted personal computing device to derive a unique identification credential by combining biometric and hardware cryptographic information, continuously authenticating users and calculating a trust score to ensure compliance with access policies, while shielding sensitive information from data collection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods (username/password, pin codes, two factor authentication, cryptographic keys) are used, then users can be authenticated to initiate a session, but the authentication is vulnerable to compromise and cannot ensure high certainty of user identity
Solution Approach 1:
The patent implements continuous authentication by repeatedly verifying user identity throughout the session using multiple factors (biometric, behavioral, contextual) rather than a single initial authentication. The system continuously calculates trust scores and performs re-authentication at intervals or when risk thresholds are exceeded, ensuring ongoing verification of user identity and device security throughout the entire session duration.
Solution Approach 2:
The patent combines multiple authentication factors (biometric data, behavioral characteristics, contextual information, device fingerprints) into a unified continuous authentication mechanism. The system merges these diverse data types to create a comprehensive trust score that provides high certainty in user identity verification, overcoming the limitations of single-factor authentication methods.
2Ease of operation
If login application or service providers collect personal information for authentication, then authentication can be performed, but personal identifying information is exposed and collected which is not desirable
Solution Approach 1:
The patent introduces a trusted authentication provider as an intermediary that handles personal information collection and processing. This mediator verifies user identity using multiple factors without requiring service providers to directly collect or store sensitive personal identifying information. The authentication provider acts as a secure intermediary that validates credentials and issues authentication tokens without exposing user personal data to service providers.
Solution Approach 2:
The patent extracts personal information collection and processing from service providers and relocates it to a dedicated trusted authentication provider. This separation ensures that service providers do not directly handle or store sensitive personal identifying information, reducing the risk of data breaches and information exposure while maintaining authentication functionality.
3Productivity
If authentication is focused on initial session initiation, then login can be established, but sessions become vulnerable to device compromise when users walk away from desks
Solution Approach 1:
The patent implements continuous authentication monitoring throughout the session by calculating trust scores at regular intervals and triggering re-authentication when users are detected as absent or when risk thresholds are exceeded. This continuous verification ensures that sessions remain secure even after initial login, preventing unauthorized access when users walk away from desks or devices are compromised.
Solution Approach 2:
The patent incorporates feedback mechanisms that continuously monitor session conditions and user behavior patterns. The system adjusts authentication requirements based on real-time risk assessments, triggering additional verification steps when abnormal patterns are detected (such as prolonged absence, location changes, or suspicious device behavior), thereby maintaining session security without unnecessarily disrupting legitimate user activity.
Data Source
AI summary
The present technology pertains to a system that authenticates the identity of a user trying to access a service. The system comprises an authentication provider configured to communicate authentication requirements to a continuous multifactor authentication device and the continuous multifactor authentication device configured to receive authentication requirements, to fuse multiple identification factors into an identification credential for a user according to the authentication requirements, and to send the authentication credential to the authentication provider. After receiving the identification credential meeting the authentication requirements, the authentication provider is configured to instruct a service provider to initiate a session.


