Multi-Factor Authentication System Using Secondary Device Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional multi-factor authentication methods are cumbersome and inefficient, particularly in online transactions, as they often require users to remember and input multiple passwords or answer personal questions, which can be vulnerable to unauthorized access.

Innovation Solution

A multi-factor authentication system that associates electronic devices with user profiles, using secondary authentication information from devices such as smart phones, tablets, and wearables, eliminating the need for additional user input by leveraging device-specific data like biometrics, MAC addresses, and location information to authenticate users without manual prompts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional multi-factor authentication methods are used, then security is improved, but user convenience deteriorates due to requiring manual input of multiple passwords or answers to personal questions

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables devices to automatically provide secondary authentication information without requiring manual user input. The electronic device autonomously retrieves and transmits authentication data (such as biometric information, MAC addresses, or location data) to the backend system, allowing the authentication process to serve itself rather than requiring continuous user intervention for each factor.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Authentication information is pre-stored in the electronic device's memory during device registration. When authentication is needed, the system retrieves this pre-prepared information automatically, eliminating the need for users to manually input multiple passwords or answers to personal questions at the time of authentication, thus improving convenience while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If secondary authentication mechanisms are added, then security against unauthorized access is improved, but the authentication process becomes more complex and cumbersome

Engineering Contradiction:
Improvesecurity against unauthorized accessVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges multiple authentication factors into a unified automated process. Instead of presenting users with separate steps for primary and secondary authentication, the electronic device combines device identification, biometric verification, and location validation into a single automated authentication transaction, reducing the perceived complexity while maintaining comprehensive security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The electronic device acts as an intermediary between the user and the authentication system. It automatically manages the complexity of retrieving, validating, and transmitting multiple authentication factors to the backend system, shielding the user from the complexity while ensuring secure multi-factor verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple passwords and personal questions are required for authentication, then authentication complexity increases, but user input burden also increases making the process inefficient

Engineering Contradiction:
Improveauthentication verificationVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The electronic device autonomously performs the authentication verification process by automatically retrieving stored authentication information and transmitting it to the backend system without requiring users to manually input multiple passwords or answers, significantly reducing the time users spend on authentication while maintaining thorough verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Authentication information is pre-stored in the device during registration, allowing the system to retrieve and verify multiple factors instantly during authentication without requiring users to spend time recalling or re-entering passwords or personal questions, thus reducing authentication time while maintaining verification reliability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12160420B1Public authentication systems and methods
Publication Date: 2024.12.03 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US12160420B1 patent drawing
  • US12160420B1 patent drawing
  • US12160420B1 patent drawing

AI summary

Techniques provided herein relate to electronic data access requests. An access system receives at least one electronic data action request from a client. At least a portion of the data access authentication information is sourced from a secondary device connected to an intermediary device. The electronic data action request is authenticated based upon the data access authentication information.