Multi-Factor Authentication System for Identity Theft Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure online communication systems face challenges in providing robust authentication methods across multiple websites, leading to potential security breaches and identity theft, especially in e-business and identity-sensitive applications.

Innovation Solution

A secure access system that creates a safe user account using strong authenticators such as voice biometrics, soft tokens, fingerprint biometrics, passwords, and PINs, allowing users to access information associated with a referring organization through a unique login and authenticator combination, with the option to enroll once and use across multiple access points.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional username-password authentication is used across multiple websites, then ease of operation is improved, but security is worsened due to potential breaches and identity theft

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system is segmented into multiple independent factors: something you know (password), something you have (token/device), and something you are (biometric). Each factor operates independently and can be evaluated separately, allowing the system to provide robust security while maintaining ease of use through the integrated authentication process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent combines multiple authentication factors into a composite authentication mechanism. Rather than relying on a single password, the system integrates biometric data, tokens, and knowledge-based credentials into a unified authentication framework that provides both security and user convenience.

Inventive Principle:
Principle #40Composite materials

2Reliability

If multiple authentication factors are required, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is designed as a universal platform that can handle multiple authentication factors through a single integrated interface. The system can accommodate various biometric types (fingerprint, facial recognition, iris scan), multiple token formats, and different password schemes, all through one unified authentication mechanism that reduces perceived complexity for users.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

An intermediary authentication service or gateway is introduced that mediates between the user and the protected resources. This intermediary handles the complexity of multi-factor authentication by coordinating between different authentication factors, verifying credentials, and making authorization decisions, thereby shielding users from the underlying system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If strong authenticators like biometrics are implemented, then security against identity theft is improved, but ease of operation is worsened due to additional registration steps

Engineering Contradiction:
Improveprotection against identity theftVSAvoidregistration process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by pre-registering and storing biometric templates and authentication factors during the initial setup phase. Once registered, these pre-configured authentication mechanisms can be quickly invoked without requiring users to perform complex actions during actual authentication, thus maintaining both security and ease of operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The biometric authentication system leverages the user's own biological characteristics as the authentication factor. The user's fingerprint, facial features, or iris pattern inherently serve as the credential, eliminating the need for users to manually create or manage complex passwords. The system automatically captures and verifies these self-service biometric data, reducing the operational burden on users.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9756028B2Methods, systems and computer program products for secure access to information
Publication Date: 2017.09.05 WORKDAY INC
  • US9756028B2 patent drawing
  • US9756028B2 patent drawing
  • US9756028B2 patent drawing

AI summary

Methods for secure communications are provided. The methods include creating a safe user account on a secure access system, wherein creating an account includes provision of at least one strong authenticator to be associated with a user of the secure access system; providing a unique login and the at least one strong authenticator associated with the user to the secure access system to gain access to information associated with a referring organization, the referring organization being registered with the secure access system; and accessing the information associated with the referring organization based on the unique login and the at least one strong authenticator provided to the secure access system. Related systems and computer program products are also provided.