Cross-Referencing Authentication Factors for Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication methods provide weak security as they treat authentication inputs independently, failing to account for correlations between them, leading to issues with false negatives due to biometric changes and vulnerability to replay attacks.
Innovation Solution
The method cross-references multiple authentication factors, including biometric inputs, to assess correlation between them, using a risk engine to generate an authentication result that considers the interdependence of these factors, enhancing security by evaluating consistency and potential attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional naive authentication is used that compares passwords and biometric readings independently, then the authentication process is simple and fast, but the security is weak and vulnerable to replay attacks
Solution Approach 1:
The patent merges multiple authentication factors (password, biometric readings, temporal data, contextual information) into a unified authentication evaluation process. Instead of treating each factor independently, the system combines them to assess overall authentication risk, thereby improving security without proportionally increasing complexity.
Solution Approach 2:
The system implements feedback mechanisms by continuously monitoring authentication factors and adjusting authentication decisions based on correlated information. Temporal data from previous authentication attempts and contextual information provide feedback that enhances security decisions while maintaining process efficiency.
2Reliability
If biometric authentication is used without cross-referencing, then the authentication is fast, but false negatives occur due to biometric drift and changes
Solution Approach 1:
The system performs preliminary actions by collecting and storing temporal data and contextual information during previous authentication sessions. This pre-collected data is then cross-referenced with current authentication attempts to account for biometric drift, improving accuracy without requiring additional real-time measurement steps.
Solution Approach 2:
The system accommodates parameter changes in biometric readings by comparing them against temporal patterns and contextual data from previous sessions. This allows the system to recognize legitimate biometric variations due to aging, health changes, or environmental factors while maintaining authentication accuracy.
3Reliability
If multiple authentication factors are cross-referenced to assess correlation, then security is improved, but the authentication process becomes more complex
Solution Approach 1:
The system performs self-service by automatically collecting, correlating, and evaluating multiple authentication factors without requiring user intervention. The cross-referencing of temporal data, contextual information, and authentication factors is handled autonomously by the system, maintaining user convenience while improving security.
4Object-affected harmful factors
If authentication factors are treated as independent inputs, then the authentication process is straightforward, but the system is vulnerable to replay attacks
Solution Approach 1:
The system performs preliminary actions by collecting temporal data and contextual information in advance, creating a baseline for detecting replay attacks. This pre-collected information enables the system to identify and reject replayed authentication attempts without adding significant complexity to the real-time authentication process.
Data Source
AI summary
A technique of authenticating a person involves obtaining, during a current authentication session to authenticate the person, a first authentication factor from the person and a second authentication factor from the person, at least one of the first and second authentication factors being a biometric input. The technique further involves performing an authentication operation which cross references the first authentication factor with the second authentication factor. The technique further involves outputting, as a result of the authentication operation, an authentication result signal indicating whether the authentication operation has determined the person in the current authentication session likely to be legitimate or an imposter. Such authentication, which cross references authentication factors to leverage off of their interdependency, provides stronger authentication than conventional naïve authentication.


