Device Profile Verification for Secure Authentication Re-enrollment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current two-factor authentication systems face challenges in efficiently re-enrolling devices, especially when users lose their devices or change phone numbers, leading to cumbersome and potentially insecure processes vulnerable to social engineering exploits.

Innovation Solution

A system and method that utilize a digital fingerprint of a device, created by a device profiling engine, to verify the status of an authentication device, allowing secure re-enrollment and additional authentication factors, leveraging device configuration characteristics and usage patterns to ensure secure token or key-based authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional re-enrollment processes are used (contacting IT admin or using pin code), then device re-enrollment can be completed, but the process becomes slow, cumbersome, and vulnerable to social engineering attacks

Engineering Contradiction:
Improveauthentication securityVSAvoidre-enrollment process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by creating a device profile during initial enrollment that captures unique device characteristics. This profile is stored and later used to automatically verify re-enrollment requests, eliminating the need for manual IT admin intervention or pin codes during re-enrollment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a digital copy of the device's unique characteristics (device profile) that can be stored and compared. This copy contains identifying information about the device that allows verification without requiring the physical device or manual authentication, enabling secure automated re-enrollment.

Inventive Principle:
Principle #26Copying

2Ease of operation

If pin code is used for re-enrollment, then device re-enrollment becomes simpler, but authentication security becomes vulnerable to pin code exploitation

Engineering Contradiction:
Improvere-enrollment processVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system replaces the mechanical pin code verification system with a device profile-based verification system. Instead of relying on user-provided pin codes that can be guessed or stolen, the system automatically compares device characteristics captured in the stored profile with the current device's profile, providing secure verification without user input.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If device profile verification is implemented, then re-enrollment security is improved and social engineering attacks are resisted, but system complexity increases

Engineering Contradiction:
Improvere-enrollment securityVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The device profile serves multiple functions: it is created during initial enrollment, stored for future verification, and used to automatically verify re-enrollment requests. This multi-functional approach consolidates what would otherwise require separate systems for enrollment, device identification, and verification into a single unified mechanism.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If manual IT admin intervention is required for re-enrollment, then security control is maintained, but processing time increases and user convenience decreases

Engineering Contradiction:
Improvesecurity controlVSAvoidre-enrollment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service re-enrollment by automatically verifying device profiles without requiring manual IT admin intervention. When a device requests re-enrollment, the system autonomously compares the submitted device profile with the stored profile and completes verification automatically, eliminating human involvement while maintaining security control.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9455988B2System and method for verifying status of an authentication device
Publication Date: 2016.09.27 CISCO TECHNOLOGY INC
  • US9455988B2 patent drawing
  • US9455988B2 patent drawing
  • US9455988B2 patent drawing

AI summary

A system and method that includes receiving a first device profile and associating the first device profile with a first application instance that is assigned as an authentication device of a first account; receiving a second device profile for a second application instance, wherein the second application instance is making a request on behalf of the first account; comparing the second device profile to the first device profile; and completing the request of the second application instance according to results of comparing the second device profile and the first device profile.