Mobile Device Multi-Factor Authentication via GPS and Hardware ID
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current two-factor authentication methods are becoming less secure due to vulnerabilities in password and personal information theft, and device reputation approaches are unreliable and easily compromised, leading to concerns about secure access to web sites and applications, especially in financial transactions.
Innovation Solution
A multi-factor authentication system that uses a mobile device's hardware ID and GPS location verification, integrating with a network provider to validate the device's location, creating a secure 'device lie-detector' that is difficult to deceive, even when SIM cards are changed or users roam.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If two-factor authentication using passwords and personal information is used, then authentication capability is provided, but security reliability deteriorates due to malware and social media exposure
Solution Approach 1:
The patent extracts the authentication verification process from traditional server-side only validation and adds a client-side component that independently verifies device identity and location. This extraction creates an additional security layer that does not rely on compromised credentials or personal information.
Solution Approach 2:
The patent introduces mobile device characteristics (hardware ID, GPS location, network provider) as an intermediary verification mechanism. Instead of directly relying on passwords or personal information, the system uses device-specific attributes as a mediator to authenticate user identity, making it harder for attackers to compromise the authentication process.
2Adaptability or versatility
If device fingerprinting is used for device identification, then device recognition capability is provided, but reliability deteriorates because software configurations change and fingerprints can be copied
Solution Approach 1:
The patent segments the device identification process into multiple independent components: hardware ID extraction, GPS location verification, and network provider identification. Instead of relying on a single device fingerprint that can be copied, the system divides identification into several factors that must all match, making replication significantly more difficult.
Solution Approach 2:
The patent adds spatial and network dimensions to device identification beyond traditional software-based fingerprinting. By incorporating GPS location coordinates and network provider information, the system creates a multi-dimensional device identity that is much harder to replicate than conventional device fingerprints alone.
3Reliability
If one-time use tokens are delivered via SMS, then second-factor authentication is provided, but security deteriorates due to potential delivery to unintended addresses or hacker redirection
Solution Approach 1:
The patent enables the mobile device to self-verify its own identity and location characteristics without requiring external verification through SMS tokens. The device autonomously provides hardware ID, GPS location, and network provider information, eliminating the need for vulnerable SMS-based second-factor authentication while maintaining strong security.
4Reliability
If additional authentication data entry is required, then security is improved, but ease of operation deteriorates reducing adoption rate
Solution Approach 1:
The patent configures the mobile device to automatically provide authentication verification data without requiring user input. The device self-extracts hardware ID, self-determines GPS location, and self-identifies network provider, eliminating the need for users to manually enter additional authentication information while maintaining strong security verification.
Data Source
AI summary
Verification of a user login to a secure account from a mobile device occurs when the user provides login credentials and a hardware identifier (ID) corresponding to the mobile device. The provided login credentials and hardware ID are then verified against a registry. Further, the mobile device determines and provides a geographic location of the mobile device using a global positioning system (GPS) component installed therein. The location provided by the mobile devices is then matched with a location of a network element with which the mobile device is currently communicating.


