Multifactor Authentication via Security Device Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication methods using a single factor, such as passwords, are insufficient to guarantee the security of access to services, as users often reuse passwords across different services, making them vulnerable to malicious access if compromised.

Innovation Solution

A multifactor authentication method that utilizes two different authentication information elements from a consulting device and a security device associated with the user account, where the security device provides an additional authentication factor, such as a unique code or localization information, to enhance security without affecting the user experience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional single-factor authentication (password) is used, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of authenticationVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into two independent parts: a first authentication information element from the consulting device and a second authentication information element from a security device. This segmentation allows the system to maintain ease of operation for the primary authentication while adding a separate security layer that does not interfere with the user experience.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A security device acts as an intermediary between the consulting device and the service. This intermediary provides the second authentication information element independently, enhancing security without requiring the user to directly interact with or manage the additional authentication factor.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multifactor authentication is implemented, then authentication security is improved, but device complexity is worsened

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security functionality is extracted from the consulting device and placed in a separate security device. This extraction reduces the complexity of the consulting device while maintaining enhanced authentication security, as the security device independently provides the second authentication information element.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If additional authentication information is required, then authentication security is improved, but ease of operation is worsened

Engineering Contradiction:
Improveauthentication securityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security device autonomously provides the second authentication information element without requiring user intervention. The device self-manages the generation and transmission of authentication data, maintaining security enhancements while preserving ease of operation for the user.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9633221B2Authentication method and devices for accessing a user account of a service on a data network
Publication Date: 2017.04.25 IDEMIA FRANCE SAS
  • US9633221B2 patent drawing
  • US9633221B2 patent drawing
  • US9633221B2 patent drawing

AI summary

An authentication method for accessing a user account of a service (28) on a data network (26), includes the following steps:reception (E20) by the service (28) of a request from a consulting device (10) for the service (28), the request including a first authentication information element,reception (E60) by the service (28) of an information element sent by an authentication security device manager (34), the information received by the service (28) being based on a second authentication information element originating from a security device (16; 18) associated with the user account, andauthentication by the service (28), based on the first authentication information element and the information received from the authentication security device manager (34).