Multifactor Network Authentication Key Fragmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network authentication systems use a fixed set of predetermined rules, which limits their ability to support a wide variety of devices with different functionalities, leading to inflexibility and inadequate security in modern networks prone to data leakage and unauthorized access.
Innovation Solution
A multifactor network authentication system that allows user-defined authentication rules, dynamically adjusts authentication levels based on device capabilities and user preferences, and splits authentication keys among multiple users, enabling flexible and enhanced security measures in response to potential threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a fixed predetermined set of authentication rules is used, then the authentication system is simple to implement, but it cannot support a wide variety of devices with different functionalities
Solution Approach 1:
The authentication system dynamically adjusts the set of authentication rules based on device capabilities and security requirements. Instead of using a fixed predetermined set, the system selects and configures authentication rules in real-time, allowing the same system to work with diverse devices while maintaining security. This is achieved through automated device capability detection and adaptive rule selection.
Solution Approach 2:
The system changes parameters of authentication rules based on device characteristics. Different devices receive different authentication configurations - for example, devices with biometric capabilities are assigned biometric authentication rules, while devices without such capabilities receive alternative authentication methods. This parameter adaptation enables broad device support without requiring a single complex fixed rule set.
2Reliability
If rigid authentication rules are enforced, then security is maintained, but devices with limited functionality cannot perform required authentication actions
Solution Approach 1:
The system applies different authentication rules locally to different devices based on their specific capabilities. Rather than enforcing a uniform rigid rule set across all devices, each device receives authentication rules tailored to its functional characteristics. For example, a mobile device with fingerprint sensor receives biometric authentication rules, while a basic device receives password-based rules, ensuring both security and operability for each device type.
Solution Approach 2:
The authentication rule set is segmented into multiple categories based on device capabilities. The system divides authentication methods into different tiers or types (biometric, device-based, knowledge-based) and assigns appropriate segments to devices based on their functionality. This segmentation allows the system to maintain security requirements while accommodating devices with limited capabilities by selecting appropriate rule segments.
3Reliability
If authentication rules are dynamically adjusted, then security is enhanced in response to threats, but the system complexity increases
Solution Approach 1:
The authentication system incorporates feedback mechanisms that monitor device behavior, authentication attempts, and security events. Based on this feedback, the system automatically adjusts authentication rules - for example, increasing authentication requirements when suspicious activity is detected or relaxing rules for trusted devices. This feedback-driven adaptation enhances security dynamically while the automated nature reduces the need for complex manual configuration.
Solution Approach 2:
The system performs self-adjustment of authentication rules based on pre-configured policies and real-time conditions. Rather than requiring complex external management, the system autonomously detects threats and modifies authentication requirements according to established security policies. This self-service capability enhances security responsiveness while minimizing the operational complexity of managing dynamic rules.
Data Source
AI summary
A network authentication device that includes an authentication engine in signal communication with a network interface. The authentication engine is configured to receive an authentication key request from a first user device that identifies an account linked with a first user and a second user device. The authentication engine is configured to generate an authentication key and to establish a first set of authentication rules for the first user and a second set of authentication rules for the second user. The authentication engine is configured to generate a first authentication key fragment comprising a first portion of the authentication key and a second authentication key fragment comprising a second portion of the authentication key and to send the first authentication key fragment to the first user device and the second authentication key fragment to the second user device.


