Multi-Factor Authentication Auditing Across Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Multi-factor authentication performed on the same device can be compromised, allowing unauthorized access, as it essentially becomes a single factor authentication, failing to provide adequate security against data breaches.

Innovation Solution

A system that audits and calculates the strength of multi-factor authentication, logs the audit trail, and applies security policies to detect anomalies, ensuring that multiple devices are used for authentication, thereby enhancing data security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If multi-factor authentication is performed on the same device, then authentication convenience is improved, but security strength deteriorates

Engineering Contradiction:
Improveauthentication convenienceVSAvoidsecurity strength
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a new dimension of device diversity to the authentication process. Instead of only considering authentication factors, it adds the dimension of device identity, requiring authentication to occur across multiple distinct devices. This dimensional expansion transforms the security model from factor-based to factor-plus-device-based authentication, effectively resolving the contradiction by maintaining convenience (same device can still authenticate) while improving security (compromise of one device does not compromise all authentication factors).

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent segments the authentication system by device, creating device-specific authentication instances. Each device becomes an independent security boundary with its own authentication context. This segmentation means that even if one device is compromised, the authentication factors on other devices remain secure, thus maintaining both operational convenience and security strength through distributed device-based authentication.

Inventive Principle:
Principle #1Segmentation

2Reliability

If device information is collected and analyzed, then security monitoring is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity monitoringVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the audit trail system multi-functional by having it serve both as a security monitoring mechanism and as a source for calculating authentication strength. The same device information collection that enables security auditing also provides the data needed to assess authentication strength, eliminating the need for separate monitoring infrastructure and reducing overall system complexity while improving security monitoring capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs self-auditing by automatically collecting device information and calculating authentication strength without requiring external monitoring systems. The authentication system itself generates the audit trail and security assessments, reducing the need for additional complex monitoring infrastructure while maintaining improved security oversight.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11762973B2Auditing of multi-factor authentication
Publication Date: 2023.09.19 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11762973B2 patent drawing
  • US11762973B2 patent drawing
  • US11762973B2 patent drawing

AI summary

In an approach to auditing of multi-factor authentication, one or more computer processors receive a request for a multi-factor authentication for a service from at least one device associated with a user. One or more computer processors retrieve information associated with the at least one device. One or more computer processors log the request and the information associated with the at least one device. One or more computer processors calculate a strength of the multi-factor authentication based on the request and the information associated with the at least one device. One or more computer processors log a multi-factor authentication audit trail.