Continuous Multi-Factor Authentication for Secure Session Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods are vulnerable to compromise, fail to ensure user identity with high certainty, expose personal information, and do not maintain secure sessions, as they are focused on initial session initiation rather than continuous verification.

Innovation Solution

A continuous multi-factor authentication system that uses a trusted personal computing device to derive a unique identification credential by combining biometric and hardware cryptographic information, continuously authenticating users and calculating a trust score to ensure compliance with access policies, while shielding sensitive information from data collection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (username/password, pin codes, two factor authentication, cryptographic keys) are used, then users can be authenticated to initiate a session, but the authentication is vulnerable to compromise and cannot ensure high certainty of user identity

Engineering Contradiction:
Improveauthentication reliabilityVSAvoididentity verification certainty
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements continuous authentication by repeatedly verifying user identity throughout the session using multiple factors (biometric, behavioral, contextual) rather than a single initial authentication. The system continuously calculates trust scores and performs re-authentication at intervals or when risk thresholds are exceeded, ensuring ongoing verification of user identity and device security throughout the entire session duration.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The patent combines multiple authentication factors (biometric data, behavioral characteristics, contextual information, device fingerprints) into a unified continuous authentication mechanism. The system merges these diverse data types to create a comprehensive trust score that provides high certainty in user identity verification, overcoming the limitations of single-factor authentication methods.

Inventive Principle:
Principle #5Merging (Combining)

2Ease of operation

If login application or service providers collect personal information for authentication, then authentication can be performed, but personal identifying information is exposed and collected which is not desirable

Engineering Contradiction:
Improveauthentication capabilityVSAvoidpersonal information exposure
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent introduces a trusted authentication provider as an intermediary that handles personal information collection and processing. This mediator verifies user identity using multiple factors without requiring service providers to directly collect or store sensitive personal identifying information. The authentication provider acts as a secure intermediary that validates credentials and issues authentication tokens without exposing user personal data to service providers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts personal information collection and processing from service providers and relocates it to a dedicated trusted authentication provider. This separation ensures that service providers do not directly handle or store sensitive personal identifying information, reducing the risk of data breaches and information exposure while maintaining authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If authentication is focused on initial session initiation, then login can be established, but sessions become vulnerable to device compromise when users walk away from desks

Engineering Contradiction:
Improvesession establishment speedVSAvoidsession security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements continuous authentication monitoring throughout the session by calculating trust scores at regular intervals and triggering re-authentication when users are detected as absent or when risk thresholds are exceeded. This continuous verification ensures that sessions remain secure even after initial login, preventing unauthorized access when users walk away from desks or devices are compromised.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The patent incorporates feedback mechanisms that continuously monitor session conditions and user behavior patterns. The system adjusts authentication requirements based on real-time risk assessments, triggering additional verification steps when abnormal patterns are detected (such as prolonged absence, location changes, or suspicious device behavior), thereby maintaining session security without unnecessarily disrupting legitimate user activity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11388011B2Accountable identities on the internet
Publication Date: 2022.07.12 CISCO TECHNOLOGY INC
  • US11388011B2 patent drawing
  • US11388011B2 patent drawing
  • US11388011B2 patent drawing

AI summary

The present technology pertains to a system that authenticates the identity of a user trying to access a service. The system comprises an authentication provider configured to communicate authentication requirements to a continuous multifactor authentication device and the continuous multifactor authentication device configured to receive authentication requirements, to fuse multiple identification factors into an identification credential for a user according to the authentication requirements, and to send the authentication credential to the authentication provider. After receiving the identification credential meeting the authentication requirements, the authentication provider is configured to instruct a service provider to initiate a session.