Password-less Authentication via Device Fingerprinting and Geo-location
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access management systems rely on passwords, which are prone to forgetting and easy to guess, and are vulnerable to identity theft techniques like spoofing and phishing, leading to security concerns and user hesitation in providing credentials.
Innovation Solution
An access management system that enables password-less authentication using device fingerprinting, geo-location, and multi-factor authentication, including out-of-band verification and biometric authentication, to ensure legitimate users can access resources securely without passwords.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If passwords are used for authentication, then users can access resources, but security is compromised due to password guessing, forgetting, and identity theft vulnerabilities
Solution Approach 1:
The patent removes passwords from the authentication system entirely. Instead of relying on secret knowledge (passwords), the system uses device-based authentication where the device itself serves as the credential. The access management system extracts and stores device fingerprints and location data, eliminating the need for user-provided passwords and thereby removing the security vulnerabilities associated with password guessing and theft.
Solution Approach 2:
The patent introduces device fingerprints and location data as intermediary authentication factors. These intermediaries bridge the gap between the user and the resource without requiring direct password entry. The access management system uses these intermediaries to verify user identity and grant access, thereby preventing identity theft and spoofing attacks that target traditional password systems.
2Reliability
If multiple authentication factors are implemented, then security against fraud is improved, but device complexity increases
Solution Approach 1:
The patent makes the access management system multi-functional by integrating multiple authentication factors (device fingerprinting, location verification, and optional biometric authentication) into a single unified system. This allows the system to provide both high security against fraud and simplified user experience, as all authentication factors work together seamlessly rather than requiring separate complex systems.
Solution Approach 2:
The patent implements self-service authentication where the device automatically provides authentication credentials without requiring manual user input for each factor. The system performs device fingerprinting and location verification automatically, and only prompts for additional biometric authentication if needed, thereby reducing the perceived complexity while maintaining multiple security layers.
3Reliability
If device registration and fingerprinting are used, then authentication reliability is improved, but loss of information about user devices occurs
Solution Approach 1:
The patent creates a copy of device identification data (device fingerprints and location information) that is stored by the access management system. This copy serves as the authentication credential, allowing the system to reliably verify user identity without requiring the user to remember or provide sensitive information. The copied data enables consistent authentication while minimizing the need to store actual passwords or sensitive user information.
Data Source
AI summary
An access management system is disclosed that can provide access to resources by password-less authentication. The access management system can provide multiple layers of security for authentication taking into account risk factors (e.g., device, location, etc.) to ensure authentication without compromising access. Contextual details of a user based on a mobile device can be used for authentication based on possession of a device. Password-less authentication of a user may be enabled by registration of devices and/or a location (e.g., a geo-graphic location) as trusted. Security data embedded with encrypted data can be sent to a first device for password-less authentication of a user at the device. A second device registered with the user can obtain the security data from the first device. The second device can decrypts the data and send the decrypted data to the access management system for verification to enable password-less authentication at the first device.


