Device Profile Verification for Secure Authentication Re-enrollment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current two-factor authentication systems face challenges in efficiently re-enrolling devices, especially when users lose their devices or change phone numbers, leading to cumbersome and potentially insecure processes vulnerable to social engineering exploits.
Innovation Solution
A system and method that utilize a digital fingerprint of a device, created by a device profiling engine, to verify the status of an authentication device, allowing secure re-enrollment and additional authentication factors, leveraging device configuration characteristics and usage patterns to ensure secure token or key-based authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional re-enrollment processes are used (contacting IT admin or using pin code), then device re-enrollment can be completed, but the process becomes slow, cumbersome, and vulnerable to social engineering attacks
Solution Approach 1:
The system performs preliminary actions by creating a device profile during initial enrollment that captures unique device characteristics. This profile is stored and later used to automatically verify re-enrollment requests, eliminating the need for manual IT admin intervention or pin codes during re-enrollment.
Solution Approach 2:
The system creates a digital copy of the device's unique characteristics (device profile) that can be stored and compared. This copy contains identifying information about the device that allows verification without requiring the physical device or manual authentication, enabling secure automated re-enrollment.
2Ease of operation
If pin code is used for re-enrollment, then device re-enrollment becomes simpler, but authentication security becomes vulnerable to pin code exploitation
Solution Approach 1:
The system replaces the mechanical pin code verification system with a device profile-based verification system. Instead of relying on user-provided pin codes that can be guessed or stolen, the system automatically compares device characteristics captured in the stored profile with the current device's profile, providing secure verification without user input.
3Reliability
If device profile verification is implemented, then re-enrollment security is improved and social engineering attacks are resisted, but system complexity increases
Solution Approach 1:
The device profile serves multiple functions: it is created during initial enrollment, stored for future verification, and used to automatically verify re-enrollment requests. This multi-functional approach consolidates what would otherwise require separate systems for enrollment, device identification, and verification into a single unified mechanism.
4Reliability
If manual IT admin intervention is required for re-enrollment, then security control is maintained, but processing time increases and user convenience decreases
Solution Approach 1:
The system enables self-service re-enrollment by automatically verifying device profiles without requiring manual IT admin intervention. When a device requests re-enrollment, the system autonomously compares the submitted device profile with the stored profile and completes verification automatically, eliminating human involvement while maintaining security control.
Data Source
AI summary
A system and method that includes receiving a first device profile and associating the first device profile with a first application instance that is assigned as an authentication device of a first account; receiving a second device profile for a second application instance, wherein the second application instance is making a request on behalf of the first account; comparing the second device profile to the first device profile; and completing the request of the second application instance according to results of comparing the second device profile and the first device profile.


