Customizable Physical Security Token for Multi-Factor Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current multi-factor authentication (MFA) methods, such as SMS OTP and advanced hardware/software-based techniques, are vulnerable to spoofing and man-in-the-middle attacks and can be difficult for non-technical users to use correctly, while also consuming significant computing and networking resources.
Innovation Solution
A system using a customizable physical security token with a grid of slots for users to place objects with visual attributes, allowing users to customize and capture images for authentication, which are compared to stored representations to grant or deny access to network resources, reducing the complexity and vulnerability of MFA.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If advanced hardware/software-based MFA techniques are used, then security against spoofing and man-in-the-middle attacks is improved, but device complexity and difficulty of operation increase
Solution Approach 1:
The patent uses a physical security token that creates a visual copy or representation of authentication data through arranged objects. Instead of complex hardware cryptographic operations, the system captures an image of the physical arrangement and uses that visual representation for authentication, simplifying the device while maintaining security.
Solution Approach 2:
The patent replaces complex mechanical/electronic hardware authentication mechanisms with a simple visual arrangement system. The physical security token uses manually arranged objects that create a visual pattern, substituting sophisticated hardware cryptography with a straightforward visual recognition system that is easier to implement and operate.
2Reliability
If advanced hardware/software-based MFA techniques are used, then security against spoofing and man-in-the-middle attacks is improved, but ease of operation for non-technical users deteriorates
Solution Approach 1:
The system creates a visual copy of authentication data through physical object arrangement. Non-technical users can simply arrange objects to match a visual pattern rather than navigating complex software interfaces or understanding cryptographic protocols, making the operation intuitive and accessible.
Solution Approach 2:
The physical security token is designed to be self-explanatory through its visual nature. Users can see the arrangement of objects and understand the authentication requirement without needing technical knowledge. The system serves itself by making the authentication mechanism inherently understandable through visual representation.
3Ease of operation
If SMS OTP MFA is used, then ease of operation is improved, but vulnerability to spoofing and man-in-the-middle attacks increases
Solution Approach 1:
Instead of transmitting authentication codes through vulnerable SMS channels, the patent creates a visual copy of authentication data through physical object arrangement. The authentication information is captured as an image of the physical arrangement, eliminating reliance on text message transmission and making spoofing or interception significantly more difficult.
Data Source
AI summary
In some implementations, an authentication system may receive, from a client device, a credential associated with a user account and a request to access a resource. The authentication system may transmit, to the client device, a request for an image of a customized physical security token associated with the user account. The authentication system may receive, from the client device, a first image. The authentication system may compare the first image with a representation of a second image of the customized physical security token associated with the user account. The authentication system may grant or denying access to the resource based on comparing the first image with the representation of the second image.


