Dynamic Multi-Factor Authentication with Adaptive Characteristic Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing two-factor authentication methods are static, making them susceptible to manipulation and theft, as the same combination of factors is always checked, lacking dynamic security measures.
Innovation Solution
A dynamic multi-factor authentication method where the type and number of factors are dynamically specified for each authentication request, with a selection of characteristics to be verified based on the authentication request, using a combination of measured values compared to reference values to determine a degree of authentication and generate an authentication token.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the same combination of factors is always checked in two-factor authentication, then the authentication process is simple and easy to implement, but the system becomes susceptible to manipulation and theft
Solution Approach 1:
The patent implements dynamic multi-factor authentication where the combination of characteristics to be verified changes for each authentication request. The system dynamically selects different subsets of characteristics from the available pool (e.g., fingerprint, face geometry, iris pattern, voice timbre, DNA) based on the authentication request, making the authentication process adaptive rather than static. This resolves the contradiction by maintaining security through variability while managing complexity through automated selection algorithms.
Solution Approach 2:
The system changes the parameters of authentication by varying which characteristics are verified and in what combination. Instead of always checking the same two factors, the system adjusts the authentication parameters dynamically - selecting different characteristics and their combinations based on the specific authentication request, thereby enhancing security without requiring manual configuration of complex authentication scenarios.
2Reliability
If multiple characteristics are verified with high authentication thresholds, then security is enhanced, but the authentication process becomes more time-consuming and complex
Solution Approach 1:
The system applies partial verification by selecting and verifying only the necessary subset of characteristics for each authentication request rather than always verifying all available characteristics. The dynamic selection process determines the optimal number and type of characteristics to verify based on the authentication context, achieving sufficient security without the time cost of exhaustive verification of all possible characteristics.
Solution Approach 2:
The authentication process dynamically adjusts the number and type of characteristics verified based on the specific request and context. This dynamic adaptation allows the system to enhance security when needed while reducing authentication time when lower security levels are sufficient, resolving the contradiction between security strength and processing time.
3Reliability
If dynamic multi-factor authentication is implemented with varying combinations of characteristics, then security against theft is improved, but the system complexity and implementation difficulty increase
Solution Approach 1:
The patent creates a universal authentication framework that can work with multiple different characteristics (fingerprint, face geometry, iris pattern, voice timbre, DNA) using the same dynamic selection and verification process. This multi-functional approach allows the system to handle various authentication scenarios through a single unified mechanism, reducing implementation complexity compared to creating separate authentication systems for each characteristic.
Solution Approach 2:
The system performs automated selection and verification of characteristic combinations without requiring manual intervention or configuration for each authentication request. The dynamic selection process is self-managing, automatically determining which characteristics to verify based on the authentication context, thereby reducing the operational complexity despite the enhanced security capabilities.
4Productivity
If less significant but easier-to-record features are used for lower authentication thresholds, then authentication speed is improved, but security level decreases
Solution Approach 1:
The system applies different quality levels of verification to different characteristics based on their significance and recording ease. Less significant but easier-to-record features (such as device properties or behavioral patterns) are used for lower authentication thresholds to enable quick authentication, while more significant characteristics are used for higher thresholds when enhanced security is required. This local differentiation resolves the contradiction by matching verification strength to the specific authentication context.
Solution Approach 2:
The authentication system dynamically adjusts which characteristics are verified and at what threshold levels based on the specific authentication request and context. This dynamic adaptation allows the system to use easier-to-record features for speed when appropriate while maintaining the option to use more secure characteristics when higher security is needed, thereby resolving the trade-off between authentication speed and security level.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method for dynamic multi-factor authentication of a user (400) by an ID provider computer system (100, 500) which has access to a database with reference values (116, 616) assigned to the user (400) for a plurality of features.The procedure includes: • Receiving an authentication request to authenticate the user (400), • Selecting a combination of attributes assigned to the user (400) to be verified for successful authentication, • Querying measurements of the attributes to be verified for authentication, • Receiving the queried measurements, • Comparing the received measurements with the reference values (116, 616) of the selected attribute combination, • Determining an authentication level of the user (400) using the degree of similarity between the measurements and the reference values (116, 616), • If the determined authentication level is above an initial threshold assigned to the authentication request, generating and sending an authentication token to confirm successful authentication of the user (400).