Multi-factor authentication with increased security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-factor authentication methods, particularly tap-to-login processes, are prone to human error, server resource inefficiencies, and unauthorized access due to location independence, necessitating improved security measures.
Innovation Solution
A method where push notifications during authentication are only sent if the mobile device and user are previously authenticated, with optional location proximity requirements, and the device must have an active session to confirm or deny login requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If push notifications are sent for every login request without prior device authentication, then users can receive authentication requests, but security is compromised and unauthorized access increases
Solution Approach 1:
The system performs preliminary device authentication and establishes an active session before allowing push notifications to be sent. This preliminary action ensures that only authenticated devices can receive authentication requests, preventing unauthorized access while maintaining ease of use for legitimate users.
Solution Approach 2:
The patent introduces an intermediary authentication session mechanism that mediates between the login request and the push notification delivery. This intermediary layer verifies device authenticity and manages the authentication state, resolving the contradiction between security and ease of operation.
2Reliability
If location verification is added to authentication process, then security against unauthorized access improves, but system complexity and processing time increase
Solution Approach 1:
The system implements location verification selectively rather than universally. Location checks are performed only when necessary based on the authentication session state and risk assessment, providing enhanced security where needed while avoiding unnecessary complexity in routine authentication scenarios.
3Reliability
If multiple authentication factors are required, then security against data breaches improves, but user convenience and authentication speed decrease
Solution Approach 1:
The authentication system dynamically adjusts the number and type of factors required based on the authentication session state, device trust level, and risk assessment. This dynamic approach provides strong multi-factor authentication when needed while allowing faster, simpler authentication for trusted devices, resolving the contradiction between security and time efficiency.
Data Source
AI summary
A multi-factor authentication method and system is provided such that a push notification during an authentication process is only received if a mobile device and user are authenticated prior to receiving the push notification. Either the mobile device itself or a second device sending the push notification may be programmed to either reject or not forward the authentication request. Additionally, using the method of the present invention, enhanced security is provided by requiring the location of the mobile device and the second device to be approximately in the same geographical location.

