Context-Switching Authentication via NFC Tap and BLE Proximity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems for accessing sensitive information over public networks are cumbersome and prone to human error due to the need for multiple user inputs, often involving third-party data providers and additional verification steps.
Innovation Solution
A method and system for context-switching authentication using Bluetooth Low Energy (BLE) links between devices, enabling a single user action, such as tapping an NFC-enabled contactless card, to authenticate a web access request on a second device, leveraging a contactless card with integrated NFC data storage and a mobile device with a reader, and generating authentication tokens for secure access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional multi-step authentication processes are used, then security is improved, but ease of operation deteriorates due to multiple user inputs and verification steps
Solution Approach 1:
The authentication system is segmented into two functional devices: a first device that performs authentication verification and a second device that receives authentication results. This segmentation allows the authentication logic to be separated from the user interface, enabling secure multi-factor authentication while simplifying user interaction to a single device operation.
Solution Approach 2:
The first device acts as an intermediary between the user's second device and the authentication system. It receives authentication requests, performs verification using stored credentials, and returns results to the second device. This intermediary role enables automated authentication without requiring the user to directly interact with multiple verification steps.
2Ease of operation
If automated authentication systems are implemented, then ease of operation is improved, but device complexity increases due to integration requirements
Solution Approach 1:
The first device is designed with multi-functionality, serving as both an authentication credential storage device and an automated verification system. It can store multiple authentication credentials and handle different authentication protocols, reducing the need for separate dedicated authentication hardware and simplifying system integration.
Solution Approach 2:
The authentication system implements self-service capabilities where the first device automatically verifies authentication credentials without requiring manual intervention. The device autonomously processes authentication requests, compares credentials, and generates verification results, reducing operational complexity despite increased automation.
Data Source
AI summary
Systems and methods is provided for implementing a strong user authentication across a public network. One operational aspect of the disclosed systems and methods involves the integration of a browser functionality to communicate with processes and hardware elements on a device initiating the network connection to implement a context-switching authentication scheme. Disclosed system and process further involves an implementation of a two-factor strong authentication based on a single authentication input from a user involving an NFC read of a contactless card by a mobile device within Bluetooth proximity of the device initiating the network connection.


