Dynamic Multifactor Authentication via Device Presence Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional multifactor authentication systems rely on static authentication processes, making them vulnerable to unauthorized access as they cannot dynamically adjust authentication levels or types based on device presence, leading to potential data exfiltration and inability to distinguish between genuine users and impersonators.

Innovation Solution

Implementing a dynamic multifactor authentication system that adjusts the number of authentication layers and types based on detected devices, using a combination of device types and presence to enhance security by increasing or reducing authentication complexity accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a static multifactor authentication process with predefined authentication requirements is used, then the authentication process is simple to implement and manage, but the system is vulnerable to unauthorized access if authentication information is compromised

Engineering Contradiction:
Improveease of authentication processVSAvoidsecurity against unauthorized access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system dynamically adjusts the number and types of authentication factors based on device presence and characteristics. Instead of using a fixed static set of authentication requirements, the system modifies authentication complexity in real-time based on detected devices, making the authentication process adaptive rather than rigid.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes authentication parameters (number of factors, types of factors) based on detected device conditions. When specific devices are detected, the system adjusts authentication requirements by adding or removing factors, thereby changing the security parameters dynamically rather than maintaining fixed parameters.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the number of authentication factors is increased to improve security, then unauthorized access is more difficult to obtain, but the authentication process becomes more complex and time-consuming

Engineering Contradiction:
Improvesecurity against unauthorized accessVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system dynamically adjusts authentication complexity based on detected devices. When high-trust devices are detected, the system reduces the number of authentication factors required, thereby decreasing authentication time. When devices are not detected or trust level is lower, the system increases factors to maintain security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes authentication parameters (number of factors) based on real-time device detection conditions. This allows the system to optimize between security and speed by adjusting parameters according to the current context rather than using a fixed high-security setting that always requires multiple factors.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If conventional authentication systems rely only on provided information to confirm user identity, then the authentication process is simple, but the system cannot detect whether authentication information is being provided by the actual user or a bad actor

Engineering Contradiction:
Improvesimplicity of authentication verificationVSAvoidaccuracy of user identity confirmation
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system introduces detected devices as intermediary evidence to verify user identity. Instead of relying solely on authentication information provided by the user, the system uses the presence and characteristics of detected devices as additional verification layers to confirm that the authentication information is being provided by the legitimate user rather than an imposter.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses device detection feedback to enhance identity verification. By continuously monitoring for expected devices and using their presence or absence as feedback, the system can distinguish between genuine users and bad actors more accurately than conventional systems that only process authentication information without contextual verification.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10853467B2Data access control using multi-device multifactor authentication
Publication Date: 2020.12.01 BANK OF AMERICA CORP
  • US10853467B2 patent drawing
  • US10853467B2 patent drawing

AI summary

An authentication device that includes an authentication engine configured to detect devices proximate to a terminal and to identify a user profile based on the detected one or more devices. The user profile identifies at least one of the detected devices in a device registry. The authentication engine is further configured to receive a data access request for a data resource and to identify authentication requirements for a multifactor authentication process for the user based on the detected devices. Identifying the authentication requirements includes setting types of authentication and a number of authentication levels that are used for performing multifactor authentication with the user. The authentication engine is further configured to execute the multifactor authentication process for the user, to determine whether the user has satisfied the authentication requirements, and to provide access to the data resource in response to determining the user has satisfied the authentication requirements.