Network Authentication Using Device Characteristics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for remote access to enterprise networks using dual-factor authentication are inconvenient for users, requiring multiple steps and separate hardware or software tokens, and may compromise security by performing verification locally on the device.

Innovation Solution

A method that collects device-specific parameters and sends them to a server for authentication, eliminating the need for separate tokens by using the device's characteristics as one authentication factor, along with a password, and performs dual-factor verification within the secure enterprise network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dual-factor authentication using hardware tokens and smart cards is implemented, then security is improved, but device complexity and user inconvenience increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the authentication factors (something I know - password, and something I have - device characteristics) into a unified authentication process. The device characteristics include hardware identifiers, software environment information, and operational parameters that are automatically collected and used for authentication without requiring separate hardware tokens or smart cards.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication system uses the computing device itself as the authentication factor, making the device universal for both access and authentication purposes. The device's inherent characteristics serve multiple functions: identification, authentication, and potentially authorization, eliminating the need for separate dedicated authentication hardware.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple separate authentication steps are required, then authentication security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary collection and verification of device characteristics during the authentication process. Device information such as hardware identifiers, software environment, and operational parameters are gathered in advance and used to generate authentication tokens automatically, eliminating the need for users to manually provide multiple authentication factors.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system performs self-service by automatically collecting device characteristics and generating authentication tokens without requiring manual user intervention for each factor. The system autonomously verifies device information and creates authentication credentials based on the device's inherent characteristics and the user's knowledge factor.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If authentication verification is performed locally on the device, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improveauthentication speedVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a server as an intermediary between the client device and the authentication system. The server receives device characteristics and authentication data from the client, performs verification of device information, and issues authentication tokens. This intermediary approach ensures that critical verification operations occur in a secure centralized location rather than on potentially compromised local devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9143494B2Method and apparatus for accessing a network
Publication Date: 2015.09.22 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9143494B2 patent drawing
  • US9143494B2 patent drawing
  • US9143494B2 patent drawing

AI summary

According to one embodiment of the present invention, there is provided a method of authorizing a computing device to access a network, comprising receiving authentication data including a user identifier from the computing device, determining whether approval to verify the authentication data is given, and where it is so determined, authorizing the device to access the network upon verification of the authentication data.