Device Authentication Agent for Multi-Factor Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems often rely on only two factors, lacking a secure method to ensure that the user is in possession of the device, which can be compromised by factor duplication or unauthorized device access.
Innovation Solution
The implementation of a device authentication agent that combines 'something you know' (password), 'something you are' (biometric data), and 'something you have' (device-specific authentication) using a software program tied to both the user and their device, ensuring the agent can only function on the device it was created for, thus verifying user possession.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional two-factor authentication is used, then ease of operation is improved, but security is worsened due to lack of device possession verification
Solution Approach 1:
The patent combines three authentication factors (something you know, something you have, and something you are) into a unified authentication process. The device authentication agent merges password verification, device possession verification, and biometric verification into a single integrated system that simultaneously checks all three factors without requiring separate authentication steps for each factor.
Solution Approach 2:
The device authentication agent acts as an intermediary component that mediates between the user, the authentication server, and the device. It verifies device possession by checking whether the authentication request originates from the authorized device, thereby enabling secure third-party authentication without requiring the user to physically present the device.
2Reliability
If device-specific authentication agent is implemented, then security against unauthorized device access is improved, but device complexity is worsened
Solution Approach 1:
The device authentication agent implements self-service by autonomously verifying device possession and managing the authentication process without requiring manual intervention. The agent automatically checks whether the authentication request originates from the authorized device and coordinates with the authentication server, thereby reducing the need for complex manual verification procedures.
Solution Approach 2:
The authentication system is segmented into distinct functional components: the device authentication agent running on the user device, the authentication server, and the biometric verification system. This segmentation allows each component to specialize in a specific authentication task, reducing overall system complexity while maintaining security.
3Reliability
If three-factor authentication is required, then protection against factor duplication is improved, but authentication time is worsened
Solution Approach 1:
The device authentication agent performs preliminary verification of device possession before initiating the full authentication process. By pre-verifying that the authentication request originates from the authorized device, the system can proceed with confidence and reduce the time required for subsequent authentication steps, as the device possession factor is already confirmed.
Solution Approach 2:
The authentication process maintains continuity by seamlessly integrating all three authentication factors into a single uninterrupted workflow. The device authentication agent continuously coordinates between password verification, device possession verification, and biometric verification without requiring the user to complete one factor before starting the next, thereby reducing overall authentication time while maintaining security.
Data Source
AI summary
Techniques for user authentication are provided. In one aspect, an authentication request form a user device may be received. The authentication request may include a username. A time stamp may be sent to the user device. An encrypted response may be received form the user device. The response may have been encrypted with a user and device specific authentication agent. The encrypted response may be based on the time stamp. The authentication agent may include user and device specific parameters.


