Peer Mobile Authentication Through Device Co-Location for Faster Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital transaction systems face challenges in ensuring the legitimacy of user authentication, as multifactor authentication methods can be time-consuming and prone to breaches, and may not guarantee the authenticity of the user.
Innovation Solution
Implementing an authentication protocol that utilizes the presence of multiple registered devices within a configurable distance of each other to dynamically adjust authentication steps, bypassing or supplementing security procedures based on device co-location to enhance legitimacy verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multifactor authentication methods are used to verify user legitimacy, then security is improved, but transaction time increases and user convenience deteriorates
Solution Approach 1:
The system performs preliminary registration of multiple user devices and establishes their spatial relationships in advance. During transaction authentication, the system already has pre-stored device identifiers and location data, allowing rapid verification without requiring real-time complex interactions between devices, thus reducing transaction time while maintaining security
Solution Approach 2:
The authentication protocol dynamically adjusts the verification process based on the transaction type and risk level. For low-risk transactions, the system can bypass certain authentication steps when devices are properly co-located, while maintaining strict verification for high-risk operations, thereby optimizing the balance between security and speed
2Device complexity
If traditional authentication protocols are used, then security procedures are simplified, but vulnerability to breaches increases
Solution Approach 1:
The system introduces a peer device as an intermediary in the authentication process. The co-located peer device acts as a trusted mediator that can vouch for the user's identity, adding a layer of security without requiring the user to directly manage complex cryptographic keys or security credentials. This intermediary approach enhances security while keeping the user experience simple
Solution Approach 2:
The system changes the authentication parameter from traditional credential-based verification to spatial relationship-based verification. By monitoring whether multiple registered devices are within a configurable distance of each other, the system transforms the authentication mechanism into a more breach-resistant model that doesn't rely on easily compromised passwords or tokens
3Reliability
If peer device verification is implemented, then authentication reliability is improved, but system complexity increases
Solution Approach 1:
The authentication system is segmented into independent modular components: device registration module, location tracking module, peer verification module, and transaction authentication module. Each module handles a specific aspect of the authentication process, making the overall complex system manageable and maintainable through clear separation of concerns
Data Source
AI summary
Embodiments include systems and techniques to perform secure transactions including processing registration information for each computing device of a plurality of computing devices having authority over a financial account. In one example, embodiments include receiving a pending transaction against the financial account from a computing device. Embodiments include executing an authentication protocol to determine the computing device is a member of the plurality of computing devices based upon the registration information, and processing data identifying another computing device within a configurable distance from the computing device. Embodiments further include the system to execute the authentication protocol to determine the other computing device is a member of the plurality of computing devices based upon the registration information and bypass a portion of a security procedure for authorizing execution of the pending transaction.


