Dynamic Multifactor Authentication via Device Presence Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional multifactor authentication systems rely on static authentication processes, making them vulnerable to unauthorized access as they cannot dynamically adjust authentication levels or types based on device presence, leading to potential data exfiltration and inability to distinguish between genuine users and impersonators.
Innovation Solution
Implementing a dynamic multifactor authentication system that adjusts the number of authentication layers and types based on detected devices, using a combination of device types and presence to enhance security by increasing or reducing authentication complexity accordingly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a static multifactor authentication process with predefined authentication requirements is used, then the authentication process is simple to implement and manage, but the system is vulnerable to unauthorized access if authentication information is compromised
Solution Approach 1:
The authentication system dynamically adjusts the number and types of authentication factors based on device presence and characteristics. Instead of using a fixed static set of authentication requirements, the system modifies authentication complexity in real-time based on detected devices, making the authentication process adaptive rather than rigid.
Solution Approach 2:
The system changes authentication parameters (number of factors, types of factors) based on detected device conditions. When specific devices are detected, the system adjusts authentication requirements by adding or removing factors, thereby changing the security parameters dynamically rather than maintaining fixed parameters.
2Reliability
If the number of authentication factors is increased to improve security, then unauthorized access is more difficult to obtain, but the authentication process becomes more complex and time-consuming
Solution Approach 1:
The system dynamically adjusts authentication complexity based on detected devices. When high-trust devices are detected, the system reduces the number of authentication factors required, thereby decreasing authentication time. When devices are not detected or trust level is lower, the system increases factors to maintain security.
Solution Approach 2:
The system changes authentication parameters (number of factors) based on real-time device detection conditions. This allows the system to optimize between security and speed by adjusting parameters according to the current context rather than using a fixed high-security setting that always requires multiple factors.
3Ease of operation
If conventional authentication systems rely only on provided information to confirm user identity, then the authentication process is simple, but the system cannot detect whether authentication information is being provided by the actual user or a bad actor
Solution Approach 1:
The system introduces detected devices as intermediary evidence to verify user identity. Instead of relying solely on authentication information provided by the user, the system uses the presence and characteristics of detected devices as additional verification layers to confirm that the authentication information is being provided by the legitimate user rather than an imposter.
Solution Approach 2:
The system uses device detection feedback to enhance identity verification. By continuously monitoring for expected devices and using their presence or absence as feedback, the system can distinguish between genuine users and bad actors more accurately than conventional systems that only process authentication information without contextual verification.
Data Source
AI summary
An authentication device that includes an authentication engine configured to detect devices proximate to a terminal and to identify a user profile based on the detected one or more devices. The user profile identifies at least one of the detected devices in a device registry. The authentication engine is further configured to receive a data access request for a data resource and to identify authentication requirements for a multifactor authentication process for the user based on the detected devices. Identifying the authentication requirements includes setting types of authentication and a number of authentication levels that are used for performing multifactor authentication with the user. The authentication engine is further configured to execute the multifactor authentication process for the user, to determine whether the user has satisfied the authentication requirements, and to provide access to the data resource in response to determining the user has satisfied the authentication requirements.

