Mobile Device Posture Authentication for Soft Token Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Soft tokens on mobile devices are vulnerable to security threats due to their complex functionality and multi-communication capabilities, making them susceptible to malicious attacks and fraud, while existing adaptive authentication techniques are limited in detecting fraudulent activity on these devices.
Innovation Solution
Collecting device posture information from mobile devices, including hardware, software, and environmental aspects, and using this information along with token codes to authenticate users to remote networks, employing a device risk engine to generate a device risk score and a device policy engine to manage access and authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If soft tokens are implemented on mobile devices with multiple communication capabilities and functions, then user convenience is improved and user does not have to carry multiple devices, but security vulnerabilities and susceptibility to malicious attacks increase
Solution Approach 1:
The patent segments the authentication system into multiple independent components: the soft token application, the device posture evaluation module, the risk engine, and the authentication server. Each component performs a specific function and can be independently secured. The device posture information is collected separately from the token code generation, allowing security validation without compromising the token functionality.
Solution Approach 2:
The patent introduces device posture information as an intermediary element between the mobile device and the authentication server. This intermediary provides additional context about the device's security state without directly exposing vulnerabilities. The posture information acts as a mediator that enables the server to make informed authentication decisions while the soft token continues to function normally.
2Reliability
If device posture information collection is implemented to detect fraudulent activity on mobile devices, then security against malicious attacks is improved, but system complexity increases
Solution Approach 1:
The patent makes the mobile device serve multiple functions: it acts as both a soft token generator and a source of device posture information. The same device that generates token codes also provides hardware, software, and environmental posture data. This multi-functionality reduces the need for separate dedicated security devices while maintaining comprehensive security monitoring.
Solution Approach 2:
The mobile device performs self-assessment of its own posture by collecting information about its hardware state, software configuration, and environmental context. The device autonomously generates and transmits this posture information to the authentication server without requiring external inspection or additional hardware, enabling the system to service its own security monitoring needs.
3Reliability
If adaptive authentication schemes collect machine-specific and user-specific information from user's computer, then authentication security is improved, but these techniques have limited utility when the attack target is the user's mobile device
Solution Approach 1:
The patent implements a dynamic authentication approach where the evaluation criteria adapt based on the device type and attack context. The system collects posture information that is specific to mobile devices (such as mobile hardware identifiers, mobile software versions, and mobile environmental context) rather than relying solely on computer-specific metrics. This dynamic adaptation enables the same authentication framework to effectively secure both computers and mobile devices.
Data Source
AI summary
An improved technique for managing access of a user of a computing machine to a remote network collects device posture information about the user's mobile device. The mobile device runs a soft token, and the collected posture information pertains to various aspects of the mobile device, such as the mobile device's hardware, software, environment, and/or users, for example. The server applies the collected device posture information along with token codes from the soft token in authenticating the user to the remote network.


