Integrated Second Factor Authentication via Physical Wires
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional two-factor authentication systems requiring a physical object for secondary verification can be inconvenient and prone to loss, as well as vulnerable to remote attacks, as they necessitate carrying a separate device that can be stolen or lost.
Innovation Solution
Integration of a secure physical entity within a computing device, connected via physical wires or near-field communication, allowing users to prove possession through unique combinations of physical selections, thereby enhancing security without the need for a separate object and preventing remote access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a separate physical object (bank card, badge, key, fob) is used for second factor authentication, then security against remote attacks is improved, but convenience deteriorates due to risk of loss and need to carry additional items
Solution Approach 1:
The patent merges the secure physical entity directly into the computing device, combining two previously separate components (the authentication object and the computing device) into a single integrated unit. This eliminates the need to carry a separate physical object while maintaining security, as the secure entity is now part of the device itself and can only be accessed through physical possession of the device.
2Reliability
If a separate physical object is used for authentication, then something you have is provided, but device complexity increases due to needing to manage multiple separate items
Solution Approach 1:
The secure physical entity is integrated within the computing device, merging what were previously two separate items into one. This reduces the number of items the user needs to manage from two (computing device plus separate authentication object) to one (the integrated computing device), thereby reducing complexity.
3Reliability
If physical wires connect the secure physical entity to physical structures, then remote access is prevented, but ease of operation may be reduced due to physical contact requirements
Solution Approach 1:
The patent uses near-field communication (NFC) wireless transmission to create a wireless copy or representation of the physical selection input. Instead of requiring direct physical contact with wired structures, the system captures physical selections through NFC, allowing the secure entity to receive input wirelessly while maintaining security. This resolves the contradiction by eliminating the need for physical wires while still preventing remote access, as NFC requires close physical proximity.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach provides robust security by ensuring that the secure physical entity can only be accessed in physical possession of the device, eliminating the risk of loss and remote attacks, while maintaining convenience by integrating the authentication mechanism directly into the computing device.
Implementation Method 1
receiving, through a wired or near-field communication (NFC) wireless transmission, a combination of physical selections
Data Source
AI summary
Techniques and apparatuses are described that enable integrated second factor authentication. These techniques and apparatuses enable the improved security of something you have without the accompanying inconvenience or chance of loss. To do so, a secure physical entity is integrated within a computing device. While this provides the something you have without a need to carry a separate object with you, the something you have also must not be able to be accessed remotely. To prevent remote access physical wires are connected from the secure physical entity to physical structures on the computing device. In this way, a hacker or cyber thief cannot convince an authentication system that the cyber attacker does indeed have the something you have because to do so the attacker must be in physical possession of the computing device.


