Mobile Device Number Verification in Multifactor Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods lack robustness in verifying the source of credentials, as they do not effectively differentiate between legitimate and unauthorized access, especially in scenarios where credentials are compromised or intercepted.
Innovation Solution
The system generates and forwards second verification data, encrypted with the verification device's key, to confirm the source device's identity by comparing attributes such as a mobile device number or other identifiers, ensuring that credentials are sent from the intended user device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods using account identifier and password are used, then ease of operation is improved, but reliability of authentication is worsened because credentials can be compromised or intercepted by unauthorized third parties
Solution Approach 1:
The patent introduces an intermediary verification process where a verification code is sent to a registered device associated with the user's mobile device number. This intermediary step mediates between the traditional password authentication and the final access grant, adding a layer of security that verifies the user possesses the registered device without significantly increasing user effort
Solution Approach 2:
The system performs preliminary verification by sending a verification code to the user's registered device before granting access. This preliminary action ensures that even if credentials are compromised, unauthorized access is blocked because the attacker would not possess the registered device to receive the verification code
2Reliability
If multifactor authentication is implemented to verify credentials, then reliability of authentication is improved, but device complexity and authentication time are worsened
Solution Approach 1:
The system implements self-service authentication where the user's own device automatically receives and displays the verification code. The user simply needs to retrieve the code from their device and enter it, without requiring manual verification steps or complex interactions with multiple systems
Solution Approach 2:
The patent uses the user's existing mobile device, which they already possess and use for communication purposes. This universal device serves multiple functions: it receives verification codes, displays them to the user, and confirms possession without requiring additional specialized hardware or complex system integrations
3Reliability
If multifactor authentication with device verification is implemented, then unauthorized access is reduced, but authentication time is increased
Solution Approach 1:
The verification code is sent to the user's registered device in advance of the authentication attempt. The code is generated and dispatched immediately upon receiving the login request, allowing for rapid delivery and minimal waiting time for the user to retrieve and enter the code
Solution Approach 2:
The patent replaces manual verification processes with automated electronic delivery of verification codes via SMS or other electronic messaging systems. This substitution of mechanical/manual verification with automated electronic processes significantly reduces the time required for authentication while maintaining security
Data Source
AI summary
Attributes of a session, between a source device and a verification device, for sending first verification data, such as a password and an account identifier, are determined. The verification device generates user device data based on an identifier, such as a mobile device number (MDN), for a user device associated with the account identifier. An identifier, such as an MDN, associated with the source device and an encryption key associated with the verification device are determined based on session attributes. Second verification data is generated based on the identifier associated with the source device. The second verification data is encrypted using the encryption key and forwarded to the verification device. The verification device decrypts the second verification data and compares the identifier for the user device to the identifier for the source device to determine whether the first verification data was sent from the user device.


