Multi-Factor Authentication Service for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing use of cloud services by organizations has exposed them to extensive data security threats, particularly due to identity theft and password hacking, which compromise sensitive data stored on external cloud services.

Innovation Solution

A method of multi-factor authentication that involves receiving data identifying a user logged-in to a cloud service after successful authentication with a first authentication factor, communicating with the user's client device to receive a second authentication factor, determining its validity, and based on that, determining and communicating a user-permission policy to the cloud service to restrict usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If cloud services are used to store sensitive information systems, then organizations can avoid IT infrastructure costs and improve manageability, but organizations are exposed to extensive data security threats

Engineering Contradiction:
ImproveIT infrastructure cost and manageabilityVSAvoiddata security threats
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an authentication service as an intermediary between users and cloud services. This service mediates authentication requests by verifying multiple authentication factors (password, security questions, biometric data) before granting access tokens to cloud services, thereby protecting against data security threats while maintaining cloud service usage

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication service performs preliminary authentication actions before users access cloud services. By pre-verifying multiple authentication factors and issuing access tokens in advance, the system prevents unauthorized access before it can occur, addressing security concerns while enabling cloud service adoption

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If traditional single-factor authentication is used, then ease of access is maintained, but vulnerability to identity theft and password hacking increases

Engineering Contradiction:
Improveease of accessVSAvoidsecurity against identity theft
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into multiple independent factors: something the user knows (password), something the user knows about (security questions), and something the user is (biometric data). The authentication service verifies each segment separately before granting access, maintaining ease of operation while significantly improving security against identity theft

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication system uses composite authentication factors combining multiple verification methods. Instead of relying on a single authentication method, the system composite verifies password, security questions, and biometric data together, creating a robust authentication mechanism that maintains ease of use while providing strong protection against hacking

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS20250158995A1Multi factor authentication
Publication Date: 2025.05.15 CORONET CYBER SECURITY LTD
  • US20250158995A1 patent drawing
  • US20250158995A1 patent drawing
  • US20250158995A1 patent drawing

AI summary

A method of multi-factor authentication, the method comprising computer executed steps, the steps comprising: from a computer of a cloud service, receiving data identifying a user logged-in to the cloud service after being successfully authenticated using a first authentication factor, communicating with a client device of the logged-in user, for receiving a second authentication factor from the logged-in user, determining whether the second authentication factor received from the logged-in user is valid, based on a result of the determining, determining a first user-permission policy for the logged-in user, and communicating the determined first user-permission policy to the computer of the cloud service, for the cloud service to base a restriction of usage of the cloud service by the logged-in user on.