MFA Device Registration Malicious Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multifactor authentication (MFA) systems face challenges in detecting malicious device registrations, which can lead to increased security risks as malicious actors gain access to information systems.

Innovation Solution

A method and system that calculate a likelihood of device registration being malicious by processing device and account properties with pre-determined rules and pre-trained machine-learning models, sending a notification when the likelihood exceeds a predetermined threshold.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual review of authenticator registrations is performed to detect malicious devices, then detection accuracy improves, but processing time and operational complexity increase significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary analysis of device properties and account properties before final registration approval. Machine learning models pre-process and evaluate registration requests, identifying suspicious patterns early in the authentication flow before malicious devices can be fully registered

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual security review processes with automated machine learning models that analyze device and account properties. This substitution of mechanical human review with computational analysis enables rapid processing of high-frequency authenticator registrations while maintaining detection capabilities

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If all authenticator registrations are reviewed to detect malicious devices, then security reliability improves, but system complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies different levels of scrutiny to different registration requests based on local characteristics. Machine learning models evaluate specific device properties and account properties individually, applying security rules selectively rather than uniformly to all registrations. This allows focused analysis on suspicious cases while streamlining legitimate registrations

Inventive Principle:
Principle #3Local quality

3Productivity

If machine learning models are used to automatically detect malicious registrations, then processing speed improves, but measurement precision may decrease compared to manual review

Engineering Contradiction:
Improveprocessing speedVSAvoiddetection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system incorporates feedback mechanisms where machine learning model predictions are continuously evaluated and refined. Detection results feed back into model training, improving precision over time. The system also provides feedback loops for security teams to review and correct model decisions, enhancing accuracy while maintaining automated processing speed

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250175464A1Detecting A Malicious Multifactor Authentication Device Registration
Publication Date: 2025.05.29 CISCO TECHNOLOGY INC
  • US20250175464A1 patent drawing
  • US20250175464A1 patent drawing
  • US20250175464A1 patent drawing

AI summary

In one embodiment, a method includes receiving a request for registering a device that is to be used for MFA of an account, receiving a plurality of device properties from the device, retrieving a plurality of account properties, calculating a likelihood for the device registration being malicious by processing the plurality of device properties and the plurality of account properties with one or more pre-determined rules and with one or more pre-trained machine-learning models, determining that the likelihood exceeds a pre-determined threshold, and sending a notification indicating that the likelihood for the device registration being malicious exceeds the pre-determined threshold in response to determining that the likelihood exceeds the pre-determined threshold.