Multifactor Device-Mesh Authentication for Low-Entropy PIN Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods, such as simple PINs, lack sufficient entropy and are vulnerable to attacks, especially in flexible work environments where users frequently switch devices and applications, leading to security challenges and user frustration.

Innovation Solution

A system and method that utilizes a device mesh to share a public key among devices, allowing for credential input on secondary devices like mice or smartwatches, and authenticates users based on geographical proximity and entropy from these devices and an authentication server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a simple PIN is used for authentication, then ease of operation is improved, but security is worsened due to insufficient entropy

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent combines multiple authentication factors (PIN, device entropy, geographic location, time, device identifiers) into a unified authentication system. The credential is generated by hashing the PIN together with entropy from the device's hardware and contextual information, creating a multi-factor authentication mechanism that maintains user convenience while significantly strengthening security through combined factors.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If a PIN Validator with encrypted random phrase is used, then security is improved, but it is vulnerable to offline attacks that can reverse the mechanism

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces device entropy and contextual factors as intermediaries between the PIN and the authentication verification. Instead of directly encrypting and storing the PIN or random phrase, the system hashes the PIN combined with device-specific entropy and contextual information. This intermediary layer prevents offline attacks because the attacker would need to simultaneously compromise the PIN, device entropy, and contextual factors, making reversal infeasible.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If users frequently switch between devices and applications, then adaptability is improved, but authentication complexity increases and user experience deteriorates

Engineering Contradiction:
Improvedevice flexibilityVSAvoidauthentication complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal authentication credential that works across multiple devices and applications. The credential is generated once using the user's PIN combined with entropy from their primary device, and then this same credential can be used for authentication on other devices in the ecosystem. This multi-functional approach allows users to switch between devices seamlessly without requiring different authentication mechanisms for each device, reducing overall complexity while maintaining adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12381869B2Multifactor contextual authentication and entropy from device or device input or gesture authentication
Publication Date: 2025.08.05 CITRIX SYSTEMS INC
  • US12381869B2 patent drawing
  • US12381869B2 patent drawing
  • US12381869B2 patent drawing

AI summary

Methods and systems for authenticating a user requesting to access one or more resources via a device are described herein. Authentication may be based on or otherwise rely on a plurality of devices. For example, aspects described herein are directed towards a system and method for receiving an authentication request from a first user device. A second user device may send a request for and receive a public key of the first user device and receive. The second user device may verify the authentication request using the public key of the first user device and perform authentication based on an authentication secret received from a user.