Multi-Device Authentication Server Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional multi-factor authentication systems are vulnerable to theft of smartphones, as thieves can access text messages and emails, allowing them to complete authentication procedures even if the device is stolen.

Innovation Solution

A system and method for multi-device multi-factor authentication that involves a server system communicating with multiple computing devices, where authentication preferences are stored in a database, and authentication information is transmitted to designated authorization providing devices, allowing for secure verification of user identity through distinct devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional multi-factor authentication using smartphone text messages is used, then authentication convenience is improved, but security is worsened because thieves can access text messages and complete authentication

Engineering Contradiction:
Improveauthentication convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system is segmented into multiple independent devices: an initiating device for starting authentication and one or more authorization providing devices for completing authentication. This segmentation ensures that possession of a single device (even if stolen) is insufficient to complete authentication, as the thief would need access to both the initiating and authorization providing devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A server system acts as an intermediary between the initiating computing device and the authorization providing computing device. The server coordinates the authentication process by receiving requests, determining appropriate authorization devices based on stored preferences, transmitting authentication information, and verifying inputs. This intermediary layer adds security by centralizing control and preventing direct communication that could be exploited.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication information is transmitted to multiple authorization providing devices, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system dynamically determines which authorization providing devices to contact based on authentication preferences stored in a database. The server system can adapt the authentication process in real-time, selecting from multiple potential authorization devices based on pre-configured preferences, making the system flexible and secure without requiring all possible devices to be actively involved in every authentication event.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11943222B2Systems and methods for multi-device multi-factor authentication
Publication Date: 2024.03.26 CAPITAL ONE SERVICES LLC
  • US11943222B2 patent drawing
  • US11943222B2 patent drawing
  • US11943222B2 patent drawing

AI summary

Systems and methods for improved security authentication are disclosed. In some embodiments, an improved system for security authentication may include a plurality of computing devices, and a server system communicatively coupled to the plurality of computing devices. The server system may be configured to receive a request for security authentication, determine an authorization providing computing device from among the plurality of computer devices based on authentication preferences stored in a database communicatively coupled to the server system, generate and transmit authentication information to the determined authorization providing computing device, receive, from an initiating computing device an authentication input, determine whether the received authentication input matches the transmitted authentication information, and complete the request for security authentication when the received authentication input matches the generated and transmitted authentication information.