Continuous Multi-Factor Authentication for Secure Location Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security breaches in secure physical locations remain a significant issue due to unauthorized access and potential espionage by both internal and external actors, with existing authentication systems being inadequate in preventing data theft and espionage within these locations.

Innovation Solution

Integration of a multi-factor authentication system with a security system that limits device capabilities of authorized individuals once inside a secure area to prevent espionage, using continuous multi-factor authentication (CMFA) to verify user identity and restrict functionalities such as photography or data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication systems are used to allow access to secure physical locations, then ease of operation is improved, but security reliability deteriorates due to inadequate prevention of data theft and espionage

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system is segmented into multiple independent factors (something you know, something you have, something you are) that must all be satisfied simultaneously. This multi-factor segmentation ensures that compromising one factor does not grant access, thereby improving security reliability while maintaining operational ease through automated verification of each factor.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A biometric authentication intermediary is introduced between the user and the secure location access. This intermediary verifies multiple authentication factors including biometric data, acting as a mediator that enhances security reliability without requiring users to manually verify each factor, thus preserving ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If device capabilities are restricted to prevent espionage, then security reliability is improved, but device functionality deteriorates

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Device capabilities are dynamically adjusted based on authentication status and location context. When a user is authenticated and within a secure location, device functions are restricted to prevent espionage. When the user exits the secure location or re-authenticates, full functionality is restored. This dynamic adaptation resolves the contradiction by making device versatility conditional rather than fixed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different device functionalities are applied in different contexts: within secure physical locations, only essential functions are permitted while espionage-capable functions (camera, microphone, data transfer) are restricted. Outside secure locations, full device functionality is available. This local quality approach ensures security reliability within sensitive contexts while preserving device versatility in general contexts.

Inventive Principle:
Principle #3Local quality

3Reliability

If continuous multi-factor authentication is implemented, then security against internal and external threats is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The continuous multi-factor authentication system operates autonomously without requiring user intervention for each verification. The system automatically collects biometric data, verifies authentication factors, and enforces device restrictions based on authentication status. This self-service approach improves security reliability through continuous verification while minimizing the perceived complexity for users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Multiple authentication factors (biometric verification, device identification, location context) are merged into a single integrated authentication system. Rather than implementing separate systems for each factor, they are combined into one unified continuous authentication process, which improves security reliability while reducing overall system complexity through consolidation.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12028349B2Protecting physical locations with continuous multi-factor authentication systems
Publication Date: 2024.07.02 CISCO TECHNOLOGY INC
  • US12028349B2 patent drawing
  • US12028349B2 patent drawing
  • US12028349B2 patent drawing

AI summary

This disclosure relates to methods, systems, and non-transitory computer-readable storage media for integrating a multi-factor authentication system with a security system. The present technology can receive authentication data descriptive of a user associated with a user device. The present technology can also permit the user to access a secure physical location. The present technology can also limit capabilities of the user device while the user is within the secure physical location.