Device Fingerprint Authentication for Account Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing online accounts lack user-friendly and secure device authentication mechanisms, making them vulnerable to unauthorized access and spoofing, especially in environments like online banking and e-commerce.
Innovation Solution
A user interface and system that allows customers to manage device-based authentication by collecting and analyzing device fingerprints, enabling customers to set preferences for access control and alerts, using a forensic database to authenticate devices and send alerts based on geographic, time, and activity restrictions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used, then ease of operation is maintained, but security and reliability are compromised due to vulnerability to unauthorized access and spoofing
Solution Approach 1:
The system automatically collects device parameters and generates device fingerprints without requiring user intervention. The forensic database autonomously assays device characteristics and compares them against stored profiles, enabling security verification without adding operational burden to the user.
Solution Approach 2:
A device fingerprinting intermediary layer is introduced between the user and the authentication system. This intermediary automatically captures device parameters, creates unique fingerprints, and verifies them against the forensic database, providing enhanced security while remaining transparent to the user.
2Reliability
If device fingerprinting is implemented, then security and reliability are improved, but device complexity increases due to multiple parameters and forensic database requirements
Solution Approach 1:
The system collects multiple device parameters (CPU attributes, memory characteristics, storage details, network configuration) that serve universal identification purposes. These same parameters are used across different authentication scenarios, making the complex data collection serve multiple security functions simultaneously.
Solution Approach 2:
Device fingerprints are assayed and stored in the forensic database in advance, before actual authentication is needed. This preliminary action creates a ready reference library of authorized device profiles, enabling rapid verification without complex real-time analysis during authentication events.
3Adaptability or versatility
If customer-managed device preferences are implemented, then adaptability and versatility are improved, but ease of operation deteriorates due to configuration complexity
Solution Approach 1:
The system provides dynamic access control preferences that can be adjusted by customers based on their needs. Device fingerprints can be updated as devices change, and access rules can be modified without requiring system reconfiguration, allowing flexible adaptation while maintaining ease of use through automated processes.
Solution Approach 2:
The system provides feedback to customers about device authentication status and access control decisions. This feedback mechanism helps users understand which devices are authorized, why certain devices are blocked, and how to adjust preferences, simplifying the configuration process through informative interaction.
Data Source
AI summary
A system and methods for customer-managed device-based authentication are disclosed. Embodiments of the invention provide a user interface that allows a customer with an on-line account to access and manage device fingerprint information that can be used to control or regulate the customer's access. Such a system can collect user input regarding device preferences related to specified devices to be used to access or to be prohibited or restricted from accessing an account. Information regarding these devices is stored in a database. The system can then assay a device fingerprint for a device to authenticate access by the device to the account based on the device preferences. In some embodiments, input can also be collected regarding alert preferences related to alerts connected with accessing the account from specified devices.


