Environmental Object Authentication for Multi-Factor Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Multi-factor authentication systems are vulnerable to nefarious actors obtaining user biometrics and credentials, which can be used to access resources, highlighting a need for enhanced security measures to verify user identity effectively.

Innovation Solution

A system that generates and stores authentication data including biometrics, credentials, and environmental data, which uses image processing techniques to identify users and objects within their environment, requiring users to select and order objects for authentication, thereby increasing security through unique object selection and order verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-factor authentication using biometrics and credentials is implemented, then security is improved, but vulnerability to information theft by nefarious actors increases

Engineering Contradiction:
Improveauthentication securityVSAvoidtheft of user information
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication process is segmented into multiple independent factors: biometric data, credentials, environmental data, and object selections. Each factor is collected and verified separately, so that compromise of one factor does not lead to complete authentication failure. The system divides the authentication challenge into discrete steps where the user selects specific objects from the environment in a specific order.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by collecting environmental data and presenting object selections to the user before the actual authentication decision is made. The user's selections of objects and their ordering are captured in advance as part of the authentication process, allowing verification against pre-stored authentication data before granting access.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If environmental data and object selection are added to authentication, then security against information theft is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The camera device performs multiple functions: capturing biometric data, collecting environmental data, identifying objects in the environment, and presenting authentication challenges to the user. This multi-functional approach consolidates what would otherwise require separate systems into a single device, reducing overall system complexity while maintaining enhanced security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system automatically performs environmental data collection, object identification, and authentication verification without requiring manual intervention for each step. The camera device self-manages the complex tasks of processing image data, identifying objects, and comparing user selections against stored authentication data, freeing users from managing the complexity.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If image processing techniques are used to identify users and objects, then authentication accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improveuser identification accuracyVSAvoidauthentication processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system processes only the necessary portions of image data required for authentication. Rather than analyzing entire environments or all captured images, the system focuses on identifying specific objects that are relevant to the authentication challenge and comparing them against stored authentication data, reducing processing time while maintaining accuracy.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240395072A1Techniques for authenticating a user
Publication Date: 2024.11.28 CISCO TECHNOLOGY INC
  • US20240395072A1 patent drawing
  • US20240395072A1 patent drawing
  • US20240395072A1 patent drawing

AI summary

This disclosure describes techniques for authenticating a user. For instance, a system may initially generate and then store authentication data for later authenticating the user. The authentication data may include biometrics data (e.g., facial recognition data), credentials data (e.g., a username, password, etc.), and/or environmental data (e.g., object(s) located within an environment). Later, the system may receive image data generated by a user device of the user. In some examples, the system may then analyze the image data using one or more facial recognition techniques in order to identify the user. The system may then use the authentication data, such as the environmental data, to determine that the image data further represents the object(s). Based on determining that the image data further represents the object(s), the system may then verify the user for access to a resource.