Mobile Device Posture Authentication for Soft Token Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Soft tokens on mobile devices are vulnerable to security threats due to their complex functionality and multi-communication capabilities, making them susceptible to malicious attacks and fraud, while existing adaptive authentication techniques are limited in detecting fraudulent activity on these devices.

Innovation Solution

Collecting device posture information from mobile devices, including hardware, software, and environmental aspects, and using this information along with token codes to authenticate users to remote networks, employing a device risk engine to generate a device risk score and a device policy engine to manage access and authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If soft tokens are implemented on mobile devices with multiple communication capabilities and functions, then user convenience is improved and user does not have to carry multiple devices, but security vulnerabilities and susceptibility to malicious attacks increase

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authentication system into multiple independent components: the soft token application, the device posture evaluation module, the risk engine, and the authentication server. Each component performs a specific function and can be independently secured. The device posture information is collected separately from the token code generation, allowing security validation without compromising the token functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces device posture information as an intermediary element between the mobile device and the authentication server. This intermediary provides additional context about the device's security state without directly exposing vulnerabilities. The posture information acts as a mediator that enables the server to make informed authentication decisions while the soft token continues to function normally.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If device posture information collection is implemented to detect fraudulent activity on mobile devices, then security against malicious attacks is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the mobile device serve multiple functions: it acts as both a soft token generator and a source of device posture information. The same device that generates token codes also provides hardware, software, and environmental posture data. This multi-functionality reduces the need for separate dedicated security devices while maintaining comprehensive security monitoring.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The mobile device performs self-assessment of its own posture by collecting information about its hardware state, software configuration, and environmental context. The device autonomously generates and transmits this posture information to the authentication server without requiring external inspection or additional hardware, enabling the system to service its own security monitoring needs.

Inventive Principle:
Principle #25Self-service

3Reliability

If adaptive authentication schemes collect machine-specific and user-specific information from user's computer, then authentication security is improved, but these techniques have limited utility when the attack target is the user's mobile device

Engineering Contradiction:
Improveauthentication securityVSAvoidapplicability to mobile devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic authentication approach where the evaluation criteria adapt based on the device type and attack context. The system collects posture information that is specific to mobile devices (such as mobile hardware identifiers, mobile software versions, and mobile environmental context) rather than relying solely on computer-specific metrics. This dynamic adaptation enables the same authentication framework to effectively secure both computers and mobile devices.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8819769B1Managing user access with mobile device posture
Publication Date: 2014.08.26 EMC IP HLDG CO LLC
  • US8819769B1 patent drawing
  • US8819769B1 patent drawing
  • US8819769B1 patent drawing

AI summary

An improved technique for managing access of a user of a computing machine to a remote network collects device posture information about the user's mobile device. The mobile device runs a soft token, and the collected posture information pertains to various aspects of the mobile device, such as the mobile device's hardware, software, environment, and/or users, for example. The server applies the collected device posture information along with token codes from the soft token in authenticating the user to the remote network.