Multi-Device Authentication via Guard Device for Secure Domain Data Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Field-users of secure mobile devices face challenges in connecting non-secured data sources with secured devices due to differences in security classification levels, leading to blocked data flow and potential security breaches.

Innovation Solution

A computing device configured to verify user identity using authentication factors from multiple authentication devices via a guard device, determining a probability of user trustworthiness and sending authentication confirmations to ensure secure data exchange between secured and non-secured domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If direct connection between secured devices and non-secured devices is blocked to maintain security, then security reliability is improved, but data flow capability deteriorates

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddata flow capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an intermediary authentication system that acts as a mediator between secured devices and non-secured devices. This authentication server receives authentication requests from non-secured devices, verifies them against secured device requirements, and facilitates controlled data exchange. The intermediary resolves the contradiction by enabling communication while maintaining security through layered authentication protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple authentication factors are required from multiple authentication devices, then authentication security is improved, but system complexity deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication devices and their authentication factors into a unified authentication system. Instead of managing separate authentication processes for each device, the system integrates them into a single authentication server that handles multiple factors (something you know, something you have, something you are) through a unified protocol. This merging reduces operational complexity while maintaining the security benefits of multi-factor authentication.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication server is designed with universal functionality to handle various types of authentication devices and factors through a common interface. It can authenticate using passwords, biometric data, hardware tokens, or combinations thereof, all through the same system architecture. This multi-functionality approach allows the system to maintain high security through diverse authentication methods without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11102200B1Secure authentication using multiple authentication factors in a non-secure domain
Publication Date: 2021.08.24 ARCHITECTURE TECH CORP
  • US11102200B1 patent drawing
  • US11102200B1 patent drawing
  • US11102200B1 patent drawing

AI summary

In general, the techniques of this disclosure describe a computing device that is configured to verify an identity of a user based on authentication factors received from multiple authentication devices. The computing device, which may be configured to operate as a server device, may receive an authentication factor from at least three authentication devices in a group of three or more authentication devices via a guard device. The computing device may determine a probability that the respective user of each respective authentication device is a particular trusted user based on the received authentication factors. If the probability exceeds a threshold authentication probability, the computing device may send an authentication confirmation to a client device.