Multi-Factor Authentication for Mobile Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile transaction authentication methods rely on only two factors: possession of a device and knowledge of a passcode, which are vulnerable to fraud, as they lack an identity verification component, thereby compromising security.
Innovation Solution
Implementing a multi-factor authentication system that includes possession of a device, knowledge of a passcode, and biometric identity verification, utilizing Subscriber Identity Module (SIM) data and various biometric techniques such as speaker recognition, facial recognition, and fingerprint recognition, to enhance security and reduce fraud.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If only possession of device and knowledge of passcode are used for authentication, then ease of operation is improved, but security is worsened due to vulnerability to fraud and unauthorized access
Solution Approach 1:
The authentication system is segmented into three distinct factors: possession of device (first factor), knowledge of passcode (second factor), and biometric identity verification (third factor). This segmentation allows each factor to be independently evaluated and combined, creating a layered security approach where compromising one factor does not necessarily compromise the entire system.
Solution Approach 2:
The patent combines multiple authentication factors (possession, knowledge, and biometric identity) into a composite authentication mechanism. This composite approach integrates different types of verification methods, similar to how composite materials combine different substances to achieve superior properties, thereby creating a more robust security system that leverages the strengths of each individual factor.
2Reliability
If multi-factor authentication including biometric verification is implemented, then security is improved, but device complexity is worsened
Solution Approach 1:
The mobile device is designed to perform multiple authentication functions using existing components. The device can verify possession through its presence, validate passcodes through its input interface, and perform biometric verification using integrated sensors (fingerprint, facial recognition, or voice recognition). This multi-functionality allows the single device to handle all three authentication factors without requiring separate hardware systems.
Solution Approach 2:
The device performs self-verification by using its own built-in sensors and processing capabilities to validate biometric data. The fingerprint sensor, camera, or microphone on the device directly captures and processes biometric information, eliminating the need for external verification equipment and reducing overall system complexity.
3Ease of operation
If simple passcodes are used for the second authentication factor, then ease of operation is improved, but security is worsened as passcodes are simple to ascertain and abuse
Solution Approach 1:
The biometric verification acts as an intermediary layer between the passcode and the authentication decision. Even if a passcode is compromised or guessed, the biometric factor serves as an additional barrier that must be overcome. This intermediary mechanism ensures that possession of the passcode alone is insufficient for authentication, thereby enhancing security while maintaining operational simplicity.
Data Source
AI summary
The following is a system in which a person may use a Cellular (Mobile) Telephone, a PDA or any other handheld computer to make a purchase. This is an example only. The process may entail any type of transaction which requires authentication, such as any financial transaction, any access control (to account information, etc.), and any physical access scenario such as doubling for a passport or an access key to a restricted area (office, vault, etc.). It may also be used to conduct remote transactions such as those conducted on the Internet (E-Commerce, account access, etc.). In the process, a multi-factor authentication is used.


