Passive Wireless Multi-Factor Authentication Using Device Proximity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-factor authentication methods require active user participation, which is inconvenient and vulnerable to security breaches, as they rely on dedicated hardware tokens or user intervention to generate and enter codes.

Innovation Solution

A passive wireless multi-factor authentication system that uses the proximity of a registered companion device to a primary device as a factor, determining proximity through wireless access points and eliminating the need for user intervention by sending a distance-measuring signal and processing authentication requests based on preconfigured radii.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated hardware tokens are used for two-factor authentication, then security is improved, but device complexity and user convenience deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the authentication factor verification with the existing mobile device that users already carry, merging the possession factor and inherence factor into a single device rather than requiring separate hardware tokens. The mobile device uses its existing sensors (accelerometer, gyroscope, camera, microphone) to provide authentication capabilities, eliminating the need for additional dedicated hardware.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The mobile device serves multiple functions: it acts as both the possession factor (the device itself) and the inherence factor (using biometric data from sensors). This multi-functional approach allows a single universal device to replace specialized hardware tokens while maintaining or enhancing security capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If mobile phones are used as possession factor, then device complexity is reduced, but ease of operation deteriorates due to requiring active user participation

Engineering Contradiction:
Improvedevice complexityVSAvoidease of operation
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The system enables self-service authentication by automatically capturing biometric data from the mobile device's sensors and performing verification without requiring active user participation. The device uses its existing sensors to continuously monitor and capture data, and the authentication process occurs automatically in the background, freeing the user from manual code entry or active verification steps.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by continuously monitoring and capturing biometric data from the mobile device's sensors before authentication is needed. The accelerometer, gyroscope, camera, and microphone are already collecting data about the user's behavior and physical characteristics, so when authentication is required, the verification can occur rapidly using pre-captured information rather than requiring real-time active user participation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If active user participation is required for authentication, then security is maintained, but ease of operation and productivity deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The authentication system operates autonomously by automatically capturing biometric data from the mobile device's sensors and performing verification without requiring active user participation. The device uses its existing sensors to continuously monitor and capture data, and the authentication process occurs automatically in the background, freeing the user from manual code entry or active verification steps.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system maintains continuous monitoring of biometric data through the mobile device's sensors, ensuring that authentication information is always available and up-to-date. This continuous action allows for rapid authentication decisions without interrupting the user's workflow, as the system is constantly gathering the necessary data in the background rather than requiring periodic manual input.

Inventive Principle:
Principle #20Continuity of useful action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enables secure, automated user authentication without requiring active user participation, enhancing convenience and security by leveraging device proximity within preconfigured radii for authentication approval.

Implementation Method 1

A proximity of a second computing device, which was previously registered with the authentication device to be used as a factor of a multi-factor authentication process involving the first computing device, is determined by the authentication device in relation to one or more wireless access points of a wireless network of the private network

Methodology Applied
Scientific EffectWireless signal propagation: Electromagnetic Propulsion

Data Source

PatentUS11720661B2Wireless multi-factor authentication based on proximity of a registered mobile device to a protected computing device at issue
Publication Date: 2023.08.08 FORTINET INC
  • US11720661B2 patent drawing
  • US11720661B2 patent drawing
  • US11720661B2 patent drawing

AI summary

Systems and methods for a passive wireless multi-factor authentication approach are provided. According to one embodiment, a user authentication request is received by a first computing device connected to a private network. The user authentication request is sent by an endpoint protection suite running on the first computing device to an authentication device associated with the private network. A proximity of a second computing device, which was previously registered with the authentication device to be used as a factor of a multi-factor authentication process involving the first computing device, is determined by the authentication device in relation to one or more wireless access points of a wireless network of the private network. The user authentication request is then processed by the authentication device based on the proximity.