Multi-Factor Authentication Device Authorization via Code Capture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-factor authentication systems face challenges in securely adding or replacing mobile devices as factors, which can lead to fraudulent device additions and compromised security.

Innovation Solution

An authentication server facilitates the authorization of a new mobile device by using an existing registered device to demonstrate proximity and ownership, through the exchange of a secret code that is displayed on the first device and captured by the second device, ensuring secure participation in the multi-factor authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a user adds or replaces mobile devices as factors in multi-factor authentication, then the system provides flexibility and convenience, but fraudulent device additions and compromised security may occur

Engineering Contradiction:
Improvedevice flexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a trusted intermediary (the existing registered mobile device) that mediates between the authentication server and the new device. The existing device displays a code that the new device captures, creating a verified chain of trust. This intermediary mechanism allows device addition while maintaining security by ensuring the new device is authorized by the legitimate user through the existing device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent requires preliminary action by the existing registered device before allowing a new device to be added. The existing device must first display a code, and only after the new device captures and verifies this code is the new device authorized. This preliminary verification step prevents unauthorized device additions and ensures the user intentionally authorizes the new device.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If existing multi-factor authentication systems allow device addition, then user convenience is improved, but the risk of fraudulent device additions increases

Engineering Contradiction:
Improvedevice addition convenienceVSAvoidfraudulent device additions
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The existing registered mobile device serves as a trusted intermediary that facilitates the addition of new devices. It displays a code that acts as a verification token, and the new device must capture and verify this code. This intermediary approach simplifies the user experience by automating the verification process while preventing fraudulent additions through the code verification mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback by having the existing device display a code that the new device must capture and verify. The authentication server receives feedback from the new device about the captured code and determines whether to authorize the new device based on this feedback. This feedback loop ensures that only authorized devices are added while maintaining user convenience.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10812476B2Authorization of another device for participation in multi-factor authentication
Publication Date: 2020.10.20 SALESFORCE INC
  • US10812476B2 patent drawing
  • US10812476B2 patent drawing
  • US10812476B2 patent drawing

AI summary

Techniques are disclosed relating to authenticating a second mobile device for participation in a multi-factor authentication process. In disclosed embodiments, a server generates an authentication decision, based on communicating with a first mobile device as a factor in the multi-factor authentication process. After receiving a request from the first mobile device to authorize participation of a second mobile device in the multi-factor authentication process, the server may generate a secret and transmit the secret to the first mobile device. The server may receive information from the second mobile device, based on the second mobile device capturing an image of a display by the first mobile device, where the display is based on the transmitted secret. In some embodiments, the server then verifies the content of the information using the secret and verifies that the information is received within a determined time interval from transmitting the secret. After verifying the content and the time interval, the server may authorize participation of and communicates with the second mobile device as a factor in the multi-factor authentication process.