Frictionless Two-Factor Authentication via Device Identifier Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional two-factor authentication systems are cumbersome for users, leading to friction and low adoption due to the need for manual code entry, which is inconvenient and prone to user forgetfulness, and they fail to adequately secure IoT devices from unauthorized access.

Innovation Solution

A method for frictionless two-factor authentication that receives device identification information from both a secured system and a network provider, allowing real-time comparison to grant access without user input, and optionally incorporates biometric and location data for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional two-factor authentication is implemented, then security is improved, but user convenience deteriorates due to manual code entry requirements

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically performs authentication by comparing device identifiers from the secured system and network provider without requiring user action. The device itself provides the authentication data through its network access, eliminating the need for manual code entry while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Device identifiers are pre-configured in the secured system before authentication is needed. When the device accesses the network, the authentication is performed automatically by comparing the pre-stored identifier with the one presented during network access, eliminating real-time user interaction.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual code entry is required for authentication, then security verification is achieved, but user friction increases leading to low adoption

Engineering Contradiction:
Improveauthentication verificationVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication data directly from the device's network access process. Instead of requiring separate code generation and entry steps, the device identifier is automatically extracted and compared during network authentication, simplifying the overall process while maintaining verification security.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If standard password authentication is used, then ease of access is improved, but security against cracking deteriorates

Engineering Contradiction:
Improveaccess easeVSAvoidsecurity against cracking
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces device identifiers from the network provider as an intermediary authentication factor. Instead of relying solely on user-chosen passwords, the system uses device-specific identifiers that are difficult to replicate, providing enhanced security while maintaining ease of access for legitimate users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3412017B1Method and apparatus for facilitating frictionless two-factor authentication
Publication Date: 2020.08.26 AVERON US INC
  • EP3412017B1 patent drawingFigure 1
  • EP3412017B1 patent drawingFigure 2
  • EP3412017B1 patent drawingFigure 3

AI summary

A method, apparatus and computer program products are provided for facilitating performing frictionless two-factor authentication. One example method includes receiving, from a first entity, an indication of a request, received at the first entity, to access an account from a device associated with a user, the indication comprising at least one instance of first device identification information of at least one device having authorization to access the account, receiving, from a second entity, second device identification information, the second device identification information determined upon the device accessing to the network address, performing a real-time comparison between the first device identification information and second device identification information, and prompting the first entity to grant the device access to the account if a match is detected between the first device identification information and second device identification information.