Secure Delayed FIDO Authentication via Cached Thermal Presence
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
FIDO authentication systems introduce an additional user step that causes delays and inefficiencies, despite addressing interoperability issues among strong authentication devices.
Innovation Solution
Implementing an always-on authentication architecture that uses a thermal sensor and secondary sensors to detect user presence, allowing seamless authentication and cached input for secure delayed FIDO authentication, which monitors user continuity and times out if excess delay is encountered.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If FIDO authentication is implemented, then security and interoperability are improved, but user operation time increases due to additional authentication steps
Solution Approach 1:
The system performs preliminary authentication by detecting user presence through thermal and motion sensors before the actual authentication request. The authentication state is cached in advance, allowing the device to automatically verify identity without requiring the user to manually initiate the authentication process, thus eliminating the time-consuming manual steps while maintaining security
Solution Approach 2:
The authentication system serves itself by automatically detecting user presence and initiating authentication workflows without user intervention. The device monitors its own authentication state continuously and autonomously completes verification processes, freeing the user from manual authentication operations while preserving FIDO security standards
2Reliability
If manual authentication steps are required, then authentication security is maintained, but user convenience and productivity deteriorate
Solution Approach 1:
The authentication system autonomously monitors user presence via sensors and automatically initiates and completes authentication workflows without requiring manual user actions. The system manages its own authentication state, caches credentials, and verifies identity in the background, making the process transparent to the user while maintaining FIDO security requirements
Solution Approach 2:
The patent replaces manual mechanical authentication actions (such as pressing buttons or entering PINs) with automated sensor-based detection systems. Thermal sensors, motion sensors, and other detectors substitute for user interactions, using environmental and behavioral data to trigger and complete authentication processes automatically
3Reliability
If authentication monitoring is continuous, then security is enhanced, but energy consumption increases
Solution Approach 1:
The system employs periodic sampling of sensor data rather than continuous monitoring. Thermal and motion sensors are activated at intervals to detect user presence, and the authentication state is refreshed periodically. This approach maintains adequate security monitoring while significantly reducing power consumption compared to continuous operation
Solution Approach 2:
The monitoring system dynamically adjusts its operation based on contextual cues. Sensors are activated only when relevant events occur (such as device pickup, screen activation, or proximity detection), and monitoring intensity varies according to the authentication state and environmental conditions, optimizing the balance between security and energy efficiency
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enables efficient and secure authentication by eliminating the need for additional user steps, maintaining security through continuous user monitoring and cached authentication, thereby reducing delays and improving user experience.
Implementation Method 1
an architecture is provided which facilitates always-on FIDO level authentication via user authentication on a device... uses a thermal sensor and secondary sensors to detect user presence
Data Source
AI summary
Systems and methods for authenticating a user of a mobile electronic device to use a FIDO (fast identification online) compliant application in the device are provided. These entail receiving a user authentication input at the mobile electronic device and caching the authentication input. While the authentication input remains cached, the user is authenticated to use the mobile electronic device via the authentication input. The mobile electronic device is then unlocked and the FIDO compliant application is opened. Secure delayed FIDO authentication is then executed by providing the cached authentication input to the FIDO compliant application to open an authenticated session of the user on the FIDO compliant application.


