Multi-Factor Authentication System Using Secondary Device Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional multi-factor authentication methods are cumbersome and inefficient, particularly in online transactions, as they often require users to remember and input multiple passwords or answer personal questions, which can be vulnerable to unauthorized access.
Innovation Solution
A multi-factor authentication system that associates electronic devices with user profiles, using secondary authentication information from devices such as smart phones, tablets, and wearables, eliminating the need for additional user input by leveraging device-specific data like biometrics, MAC addresses, and location information to authenticate users without manual prompts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional multi-factor authentication methods are used, then security is improved, but user convenience deteriorates due to requiring manual input of multiple passwords or answers to personal questions
Solution Approach 1:
The system enables devices to automatically provide secondary authentication information without requiring manual user input. The electronic device autonomously retrieves and transmits authentication data (such as biometric information, MAC addresses, or location data) to the backend system, allowing the authentication process to serve itself rather than requiring continuous user intervention for each factor.
Solution Approach 2:
Authentication information is pre-stored in the electronic device's memory during device registration. When authentication is needed, the system retrieves this pre-prepared information automatically, eliminating the need for users to manually input multiple passwords or answers to personal questions at the time of authentication, thus improving convenience while maintaining security.
2Reliability
If secondary authentication mechanisms are added, then security against unauthorized access is improved, but the authentication process becomes more complex and cumbersome
Solution Approach 1:
The system merges multiple authentication factors into a unified automated process. Instead of presenting users with separate steps for primary and secondary authentication, the electronic device combines device identification, biometric verification, and location validation into a single automated authentication transaction, reducing the perceived complexity while maintaining comprehensive security.
Solution Approach 2:
The electronic device acts as an intermediary between the user and the authentication system. It automatically manages the complexity of retrieving, validating, and transmitting multiple authentication factors to the backend system, shielding the user from the complexity while ensuring secure multi-factor verification.
3Reliability
If multiple passwords and personal questions are required for authentication, then authentication complexity increases, but user input burden also increases making the process inefficient
Solution Approach 1:
The electronic device autonomously performs the authentication verification process by automatically retrieving stored authentication information and transmitting it to the backend system without requiring users to manually input multiple passwords or answers, significantly reducing the time users spend on authentication while maintaining thorough verification.
Solution Approach 2:
Authentication information is pre-stored in the device during registration, allowing the system to retrieve and verify multiple factors instantly during authentication without requiring users to spend time recalling or re-entering passwords or personal questions, thus reducing authentication time while maintaining verification reliability.
Data Source
AI summary
Techniques provided herein relate to electronic data access requests. An access system receives at least one electronic data action request from a client. At least a portion of the data access authentication information is sourced from a secondary device connected to an intermediary device. The electronic data action request is authenticated based upon the data access authentication information.


