Dynamic Multi-Factor Authentication Device Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional multi-factor authentication (MFA) methods can be inflexible and user-unfriendly, particularly when mobile devices lack network connectivity or when users have multiple devices, making authentication processes difficult or impossible.
Innovation Solution
The system allows users to specify preferred devices for receiving authentication codes and uses machine learning and statistical models to proactively determine the most suitable secondary device based on user behavior patterns, enabling seamless MFA without additional user effort.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional MFA sends authentication code to a predetermined mobile device, then security is enhanced, but user experience deteriorates when the device lacks network connectivity or is not accessible
Solution Approach 1:
The patent implements dynamic selection of authentication delivery mechanisms based on real-time device state and user behavior. Instead of a fixed predetermined device, the system evaluates current conditions (network connectivity, device accessibility, behavioral patterns) and dynamically chooses the most appropriate delivery method, resolving the contradiction between security reliability and operational ease
Solution Approach 2:
The system performs automatic determination of the optimal authentication delivery mechanism without requiring user intervention. The service autonomously evaluates device states, analyzes behavioral data, and selects the appropriate secondary device or mechanism, making the authentication process seamless while maintaining security
2Reliability
If MFA requires a code to be sent to a mobile device, then security is improved, but authentication becomes difficult or impossible when the mobile device is unavailable
Solution Approach 1:
The patent enables the authentication system to function through multiple delivery mechanisms (SMS, voice calls, push notifications to different devices, email) rather than relying on a single mobile device. This multi-functionality ensures authentication can proceed through alternative channels when the primary device is unavailable, enhancing both adaptability and security
Solution Approach 2:
The system pre-configures multiple secondary authentication devices and mechanisms for each user account. When authentication is needed, the system has already-established alternatives ready to deploy, eliminating the need for users to manually select or configure backup methods during the authentication process
3Reliability
If the system uses multiple secondary authentication devices, then authentication reliability improves, but system complexity increases
Solution Approach 1:
The system automatically manages the complexity of multiple authentication devices through self-service mechanisms. The service autonomously determines which secondary device to use based on real-time conditions and behavioral analysis, eliminating the need for users to manually configure or select among multiple devices. This automation hides the system complexity while maintaining high authentication availability
Solution Approach 2:
The system dynamically changes operational parameters (device selection, delivery mechanism type) based on evaluated conditions without changing the underlying system architecture. By adjusting which device or method is used rather than redesigning the system structure, the patent maintains reliability while managing complexity
Data Source
AI summary
A user initializes multi-factor authentication for a user account, wherein the user account is accessed from multiple user devices. User behavior data is stored in response to receiving login credentials for one of the multiple user devices and the user behavior data is provided as input criteria for a statistical model or machine-learning algorithm. The statistical model or machine-learning algorithm may determine, based on a set of rules, an ideal secondary user device for use in receiving a multi-factor authentication code. The secondary user device receives the multi-factor authentication code without further requests made by the user.


