Multi-Factor Authentication Device Authorization via Code Capture
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-factor authentication systems face challenges in securely adding or replacing mobile devices as factors, which can lead to fraudulent device additions and compromised security.
Innovation Solution
An authentication server facilitates the authorization of a new mobile device by using an existing registered device to demonstrate proximity and ownership, through the exchange of a secret code that is displayed on the first device and captured by the second device, ensuring secure participation in the multi-factor authentication process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a user adds or replaces mobile devices as factors in multi-factor authentication, then the system provides flexibility and convenience, but fraudulent device additions and compromised security may occur
Solution Approach 1:
The patent introduces a trusted intermediary (the existing registered mobile device) that mediates between the authentication server and the new device. The existing device displays a code that the new device captures, creating a verified chain of trust. This intermediary mechanism allows device addition while maintaining security by ensuring the new device is authorized by the legitimate user through the existing device.
Solution Approach 2:
The patent requires preliminary action by the existing registered device before allowing a new device to be added. The existing device must first display a code, and only after the new device captures and verifies this code is the new device authorized. This preliminary verification step prevents unauthorized device additions and ensures the user intentionally authorizes the new device.
2Ease of operation
If existing multi-factor authentication systems allow device addition, then user convenience is improved, but the risk of fraudulent device additions increases
Solution Approach 1:
The existing registered mobile device serves as a trusted intermediary that facilitates the addition of new devices. It displays a code that acts as a verification token, and the new device must capture and verify this code. This intermediary approach simplifies the user experience by automating the verification process while preventing fraudulent additions through the code verification mechanism.
Solution Approach 2:
The system implements feedback by having the existing device display a code that the new device must capture and verify. The authentication server receives feedback from the new device about the captured code and determines whether to authorize the new device based on this feedback. This feedback loop ensures that only authorized devices are added while maintaining user convenience.
Data Source
AI summary
Techniques are disclosed relating to authenticating a second mobile device for participation in a multi-factor authentication process. In disclosed embodiments, a server generates an authentication decision, based on communicating with a first mobile device as a factor in the multi-factor authentication process. After receiving a request from the first mobile device to authorize participation of a second mobile device in the multi-factor authentication process, the server may generate a secret and transmit the secret to the first mobile device. The server may receive information from the second mobile device, based on the second mobile device capturing an image of a display by the first mobile device, where the display is based on the transmitted secret. In some embodiments, the server then verifies the content of the information using the secret and verifies that the information is received within a determined time interval from transmitting the secret. After verifying the content and the time interval, the server may authorize participation of and communicates with the second mobile device as a factor in the multi-factor authentication process.


