Multi-Factor Authentication Service for Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing use of cloud services by organizations has exposed them to extensive data security threats, particularly due to identity theft and password hacking, which compromise sensitive data stored on external cloud services.
Innovation Solution
A method of multi-factor authentication that involves receiving data identifying a user logged-in to a cloud service after successful authentication with a first authentication factor, communicating with the user's client device to receive a second authentication factor, determining its validity, and based on that, determining and communicating a user-permission policy to the cloud service to restrict usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If cloud services are used to store sensitive information systems, then organizations can avoid IT infrastructure costs and improve manageability, but organizations are exposed to extensive data security threats
Solution Approach 1:
The patent introduces an authentication service as an intermediary between users and cloud services. This service mediates authentication requests by verifying multiple authentication factors (password, security questions, biometric data) before granting access tokens to cloud services, thereby protecting against data security threats while maintaining cloud service usage
Solution Approach 2:
The authentication service performs preliminary authentication actions before users access cloud services. By pre-verifying multiple authentication factors and issuing access tokens in advance, the system prevents unauthorized access before it can occur, addressing security concerns while enabling cloud service adoption
2Ease of operation
If traditional single-factor authentication is used, then ease of access is maintained, but vulnerability to identity theft and password hacking increases
Solution Approach 1:
The authentication process is segmented into multiple independent factors: something the user knows (password), something the user knows about (security questions), and something the user is (biometric data). The authentication service verifies each segment separately before granting access, maintaining ease of operation while significantly improving security against identity theft
Solution Approach 2:
The authentication system uses composite authentication factors combining multiple verification methods. Instead of relying on a single authentication method, the system composite verifies password, security questions, and biometric data together, creating a robust authentication mechanism that maintains ease of use while providing strong protection against hacking
Data Source
AI summary
A method of multi-factor authentication, the method comprising computer executed steps, the steps comprising: from a computer of a cloud service, receiving data identifying a user logged-in to the cloud service after being successfully authenticated using a first authentication factor, communicating with a client device of the logged-in user, for receiving a second authentication factor from the logged-in user, determining whether the second authentication factor received from the logged-in user is valid, based on a result of the determining, determining a first user-permission policy for the logged-in user, and communicating the determined first user-permission policy to the computer of the cloud service, for the cloud service to base a restriction of usage of the cloud service by the logged-in user on.


