P2P Proximity Authentication for Enterprise Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current multifactor authentication schemes fail to verify whether a rogue attacker has intercepted a one-time password from a remote location or spoofed the device location, compromising security by assuming the integrity of secondary devices.

Innovation Solution

Implementing a peer-to-peer secure mode authentication mechanism that uses proximity between a primary and secondary device as a factor, ensuring authentication occurs only when the user is in close proximity to the secondary device, with compliance rules and access tokens managed by a management service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional multifactor authentication is used, then authentication can be performed with existing devices, but security is compromised because the system cannot verify device integrity or location authenticity

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a peer device as an intermediary that vouches for the authenticity and location of the target device. This peer device acts as a trusted mediator that provides cryptographic proof and location verification, resolving the security issue without requiring complex centralized verification infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent combines multiple verification mechanisms (cryptographic proof, location verification, peer device attestation) into a unified authentication flow. By merging these verification methods into the existing multifactor authentication process, the system enhances security without adding separate complex systems.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If device proximity is required for authentication, then security against remote attacks is improved, but the authentication process becomes more complex and slower

Engineering Contradiction:
Improveprotection against remote attacksVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs proximity verification and peer device validation in advance during the authentication setup phase. By pre-establishing trusted peer relationships and verifying device proximity before critical authentication events, the system avoids time-consuming verification steps during actual authentication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses cryptographic copies and proofs of device identity and location that can be rapidly verified. Instead of performing complex real-time analysis, the system uses pre-generated cryptographic proofs that can be quickly validated, reducing authentication time while maintaining security.

Inventive Principle:
Principle #26Copying

3Reliability

If continuous proximity monitoring is implemented, then unauthorized access is prevented, but system resource consumption increases

Engineering Contradiction:
Improveaccess control securityVSAvoiddevice energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements periodic proximity checks rather than continuous monitoring. The system verifies device proximity at scheduled intervals and at key authentication events, reducing energy consumption while maintaining security by checking at sufficient frequency to detect unauthorized access attempts.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS12598182B2Peer-to-peer secure mode authentication
Publication Date: 2026.04.07 OMNISSA LLC
  • US12598182B2 patent drawing
  • US12598182B2 patent drawing
  • US12598182B2 patent drawing

AI summary

The present disclosure relates to peer-to-peer (P2P) secure mode authentication. A secondary client device can request access to an enterprise resource. The secondary client device can establish a P2P communication channel with a primary client device during a P2P secure mode. The secondary client device can determine a proximity of the computing device to the client device and generate proximity data based at least in part on the proximity of the computing device to the client device. The secondary client device can receive an authorization to access the enterprise resource based at least in part on the proximity data and access the enterprise resource by loading the enterprise resource within a sandboxed environment.