Two-Factor Authentication via Dual VPN Connections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing two-factor authentication methods for remote access are cumbersome, requiring repeated authentication when accessing work resources, which increases security risks due to vulnerabilities in remote connections.

Innovation Solution

A system and method utilizing two virtual private network (VPN) connections between a server and devices, where initial authentication of a first device grants access to network resources, and subsequent authentication of a second device through the first device maintains access without requiring repeated authentication, with token-based verification for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional two-factor authentication is used for each access, then security is maintained, but user convenience deteriorates due to repeated authentication requirements

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary two-factor authentication when the first device establishes initial VPN connectivity to the network. Once authenticated, the first device receives authorization to facilitate connections for additional devices without requiring repeated two-factor authentication, thus maintaining security while improving convenience for subsequent access operations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The first device acts as an intermediary between subsequent devices and the authentication system. After the first device is authenticated, it serves as a mediator that enables other devices to connect to the network without direct authentication involvement from users, reducing authentication overhead while maintaining security through the established trusted connection

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple devices are allowed to access network resources, then productivity improves, but security risks increase due to more connection points

Engineering Contradiction:
Improveremote work capabilityVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system segments authentication into two distinct phases: initial two-factor authentication for the first device, and simplified authentication for subsequent devices. This segmentation allows multiple devices to access network resources for improved productivity while maintaining security by requiring strong authentication only once, with subsequent access controlled through the established trusted connection

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication credentials and security context from the first authenticated device are effectively copied to subsequent devices that connect through it. This allows multiple devices to access network resources without requiring separate authentication for each, improving productivity while maintaining security through the inherited authentication context from the originally authenticated device

Inventive Principle:
Principle #26Copying

3Reliability

If VPN connections are encrypted for security, then security is improved, but connection complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidconnection complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges multiple encrypted VPN connections into a single authenticated session. The first device establishes one encrypted VPN connection with full authentication, and subsequent devices share this authentication context. This merging approach maintains security through encryption while reducing connection complexity by eliminating the need for separate authentication processes for each device

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11025592B2System, method and computer-accessible medium for two-factor authentication during virtual private network sessions
Publication Date: 2021.06.01 CAPITAL ONE SERVICES LLC
  • US11025592B2 patent drawing
  • US11025592B2 patent drawing
  • US11025592B2 patent drawing

AI summary

An exemplary system, method, and computer-accessible medium for authenticating a second device, can include initiating a first network connection between a server and a first device, initiating a second network connection between the server and the second device, and authenticating the second device based on the first network connection and the second network connection. Access to a network resource(s) can be granted to the second device based on the authentication. Access to the network resource(s) by the second device can be revoked if the first network connection is severed. The first network connection can be a first encrypted network connection and the second network connection can be a second encrypted network connection. The first network connection can be a first virtual private network (“VPN”) connection and the second network connection can be a second VPN connection.