Multi-Device Authentication via Segmented Channels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current two-factor authentication systems are vulnerable to phishing and man-in-the-middle attacks, as they rely on both authentication factors being entered into the same device and channel, lacking protection against spoofing and interception of credentials.
Innovation Solution
Implementing a multi-factor authentication system that requires authentication credentials to be entered into multiple devices through different channels, incorporating a third factor such as a biometric to verify user identity, ensuring that credentials originate from the actual user.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If two-factor authentication uses the same device and channel for both factors, then the system is simpler to implement, but it becomes vulnerable to phishing and man-in-the-middle attacks
Solution Approach 1:
The patent divides the authentication process into separate segments: first factor authentication on a first device/channel and second factor authentication on a second device/channel. This segmentation prevents attackers from intercepting both factors through phishing or man-in-the-middle attacks, as each factor must be authenticated through separate, independent channels.
Solution Approach 2:
The patent introduces an intermediary authentication server that coordinates between multiple devices and channels. The server receives first factor credentials from a first device/channel and second factor credentials from a second device/channel, then verifies both factors before granting access. This intermediary acts as a mediator that ensures both factors are authenticated through separate, secure channels.
2Reliability
If multiple devices and channels are required for authentication, then protection against phishing and spoofing is improved, but the authentication process becomes more complex
Solution Approach 1:
The patent implements self-service authentication where the authentication server automatically coordinates the multi-device, multi-channel process without requiring manual intervention. The server handles credential verification, device identification, and authentication coordination automatically, reducing the operational burden on users while maintaining high security.
Data Source
AI summary
Systems and methods of the present invention provide for a first and second client computer configured to receive and transmit an authentication credential and at least one additional authentication credential respectively. The authentication credentials may be selected from authentication credentials known only to a user, identifying a client computer and/or identifying a characteristic unique to the user. A server computer communicatively coupled to the network may be configured to receive the authentication credentials and verify the identity of the user via a match, in a database, of a first authentication credential, a second authentication credential and a third authentication credential.


