Dynamic Multi-Factor Authentication Challenge Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication systems face inefficiencies and security vulnerabilities due to complex password management and exposure issues, particularly with the rise of IoT devices and increasing data complexity, leading to limited data security and operational inefficiencies.
Innovation Solution
A computer-implemented method generates a dynamic multi-factor authentication challenge combining user-defined, biometric, and activity-based authentication factors, using machine learning models to adapt and tailor security procedures, thereby enhancing security verification and reducing user input requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional password-based authentication is used, then users can access data, but data security is compromised due to password exposure and theft
Solution Approach 1:
The authentication system is segmented into multiple independent factors (biometric data, device information, location data, time stamps) rather than relying on a single password. Each factor contributes to the overall authentication decision, making the system more secure as compromising one factor does not grant access.
Solution Approach 2:
The system introduces an intermediary authentication server that processes biometric data and device information to generate authentication tokens. This intermediary layer protects users from directly exposing sensitive credentials while maintaining security verification.
2Reliability
If multi-factor authentication is implemented, then data security is improved, but operational efficiency decreases due to complex verification procedures
Solution Approach 1:
The authentication system dynamically adjusts the combination of verification factors based on risk assessment, user context, and device trust levels. Not all authentication factors are required for every login attempt, allowing the system to balance security with operational efficiency by adapting verification requirements in real-time.
Solution Approach 2:
The system performs automated risk assessment and authentication factor selection without requiring user input for each verification step. The authentication server automatically evaluates device information, location data, and time stamps to determine the appropriate authentication flow, reducing user burden while maintaining security.
3Reliability
If password complexity requirements are increased, then security is improved, but user convenience deteriorates due to forgotten passwords and complex entry
Solution Approach 1:
The system replaces manual password entry (mechanical input) with automated biometric verification (optical/acoustic sensing). Fingerprint scanners, facial recognition, and voice authentication eliminate the need for users to type complex passwords, significantly improving ease of operation while maintaining or enhancing security.
4Adaptability or versatility
If authentication factors are dynamically combined, then adaptability to various situations is improved, but system complexity increases
Solution Approach 1:
The authentication server is designed with universal functionality to handle multiple types of authentication factors (biometric, device information, location, time) through a single unified platform. This multi-functional design allows dynamic combination of factors without requiring separate systems for each authentication method, managing complexity while maintaining versatility.
Data Source
AI summary
A computer-implemented method, according to one approach, includes: generating a multi-factor authentication challenge for a user in response to receiving a request from the user, The multi-factor authentication challenge includes a dynamic combination of available authentication factors corresponding to the user. The dynamic combination of authentication factors includes (i) at least one user defined authentication factor, (ii) at least one biometric authentication factor, and (iii) at least one activity-based authentication factor. Inputs are also received for the multi-factor authentication challenge, and a determination is made as to whether the inputs received satisfy the multi-factor authentication challenge.


