Frictionless Multi-Factor Authentication via Device and Biometric Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-factor authentication (MFA) systems face challenges due to the friction associated with requiring users to enter one-time-passwords (OTPs), leading to user dissatisfaction and potential disablement of MFA.
Innovation Solution
The implementation of frictionless multi-factor authentication (fMFA) that uses the identification of a user interface device and the user's behavioral data to create a biometrics match assessment and a unique device identifier, eliminating the need for OTPs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional multi-factor authentication requiring OTP entry is implemented, then security is improved, but user convenience and authentication speed deteriorate
Solution Approach 1:
The system performs authentication automatically without requiring user action beyond initial login. The frictionless MFA service collects device attributes and behavioral data, generates UDID and biometrics match assessment, and completes authentication autonomously, eliminating the need for users to manually enter OTPs while maintaining security
Solution Approach 2:
The system pre-collects device attributes (UDID components) and behavioral biometrics data during normal usage before authentication is needed. This preliminary data collection enables rapid automated authentication without requiring users to gather or input additional information at the moment of authentication
2Reliability
If traditional multi-factor authentication requiring OTP entry is implemented, then security is improved, but authentication time increases
Solution Approach 1:
The system pre-collects device attributes (UDID components) and behavioral biometrics data during normal usage before authentication is needed. This preliminary data collection enables rapid automated authentication without requiring users to gather or input additional information at the moment of authentication
Solution Approach 2:
The system replaces the manual mechanical process of OTP generation, transmission, and entry with an automated electronic system. The frictionless MFA service automatically compares device UDID and behavioral biometrics against stored profiles, eliminating the time-consuming manual OTP entry process while maintaining security verification
3Ease of operation
If frictionless multi-factor authentication using behavioral data and device identification is implemented, then user convenience is improved, but system complexity increases
Solution Approach 1:
The authentication system is divided into distinct functional modules: a frictionless MFA service that coordinates authentication, a UDID component that generates device identifiers from attributes, and a passive biometrics component that analyzes behavioral data. This segmentation allows each component to specialize in specific tasks, managing complexity through modular design
4Speed
If frictionless multi-factor authentication using behavioral data and device identification is implemented, then authentication speed is improved, but data processing requirements increase
Solution Approach 1:
The system uses partial action by selecting and comparing only key device attributes and specific behavioral biometrics features rather than processing all available data. This selective approach achieves sufficient authentication accuracy while reducing computational energy requirements compared to exhaustive data analysis
Data Source
AI summary
Devices, methods, and computer-readable media that perform frictionless multi-factor authentication. In one embodiment, a server includes a memory including a frictionless multi-factor authentication (fMFA) service, and an electronic processor communicatively coupled to the memory. The electronic processor is configured to receive a frictionless multi-factor authentication (fMFA) request and collected data of a user interface device, determine, with a unique device identifier (UDID) component, a unique device identifier (UDID) of the user interface device based on device attributes included in the collected data, determine, with a passive biometrics component, a biometrics match assessment against a historical profile, determine whether a user of the user interface device is authenticated under multi-factor authentication (MFA) based on the UDID and the biometrics match assessment, responsive to determining that the user is authenticated under multi-factor authentication (MFA), output a fMFA authentication response that indicates authentication of the user.


