Multifactor Authentication System Using Device Data Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current online authentication methods, such as those used in internet commerce and online banking, rely on single factors like usernames and passwords, which are vulnerable to theft, leading to potential identity theft and unlawful account access.

Innovation Solution

A computer security system that establishes a trust between a server machine and a security agent on a user's machine, using a session key for encrypted communication, and extracts device data to create a unique identity profile, incorporating multiple factors of authentication including username/password, device information, and biometric data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If single factor authentication (username and password) is used, then ease of operation is improved, but security is worsened due to vulnerability to theft and hacking

Engineering Contradiction:
Improveauthentication processVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system is segmented into multiple independent factors: knowledge-based (username/password), possession-based (device identifier), and biometric-based authentication. Each factor operates independently and contributes to the overall authentication decision, making the system more secure while maintaining operational ease through automated multi-factor verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication mechanism uses a composite approach by combining multiple authentication factors (username, password, device identifier, biometric data) into a unified authentication framework. This composite structure ensures that compromise of one factor does not lead to complete system failure, thereby improving reliability while preserving ease of operation.

Inventive Principle:
Principle #40Composite materials

2Reliability

If multiple factors of authentication are implemented, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically collects device identifiers and biometric data without requiring manual configuration or complex user setup. The authentication framework self-manages the integration of multiple factors, reducing the perceived complexity for users while maintaining high security standards through automated multi-factor verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The authentication system is designed to be universal by accommodating multiple authentication factors through a single integrated framework. This multi-functional approach allows the system to handle username/password, device identifiers, and biometric data uniformly, reducing overall system complexity despite the presence of multiple authentication mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If device data extraction is performed to create unique identity profile, then security is improved through unique identification, but loss of information is worsened due to collection of device data

Engineering Contradiction:
Improveunique identificationVSAvoiddevice data
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system extracts only the necessary device identifier information required for unique identification and authentication purposes. By selectively extracting only the essential data elements needed for security verification, the system minimizes information collection while maintaining reliable unique identification capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9426134B2Method and systems for the authentication of a user
Publication Date: 2016.08.23 VERIENT
  • US9426134B2 patent drawing
  • US9426134B2 patent drawing
  • US9426134B2 patent drawing

AI summary

A computer security system used to identify and authenticate a user. In one aspect, a method for identifying and authenticating a user is provided. The method includes establishing a trust between a server machine and an agent on a user machine. The method further includes establishing a session key to encrypt communications between the server machine and the agent. The method also includes receiving a username and password for use in validating the user. Additionally, the method includes creating an executable binary for the extraction of device data from the user machine to uniquely identify the machine. In another aspect, a computer-readable medium including a set of instructions that when executed by a processor causes the processor to identify and authenticate the user is provided. In a further aspect, a system for identifying and authenticating a user is provided.