Policy Engine Authenticator Device Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The use of mobile devices as authenticators in two-factor authentication systems poses security risks due to their vulnerable software environment, making it challenging for organizations to balance security and usability between dedicated hardware tokens and mobile devices.
Innovation Solution
A system and method that defines, evaluates, and enforces policies on computing devices to determine their suitability as authenticators by assessing their software state and potential weaknesses, using a policy engine and authenticator components to ensure the device's integrity and security before allowing its use in authentication processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If mobile devices are used as authenticators instead of hardware tokens, then usability and convenience are improved, but security and integrity are worsened
Solution Approach 1:
The patent introduces a policy engine as an intermediary between the mobile device and the authentication system. This policy engine evaluates the mobile device's software state, checks for vulnerabilities, and determines whether the device meets security policies before allowing authentication. This mediator enables the use of mobile devices (improving usability) while maintaining security through policy enforcement.
2Device complexity
If mobile devices are used as authenticators, then management complexity is reduced, but vulnerability to attacks increases
Solution Approach 1:
The patent implements preliminary security assessments by evaluating the mobile device's software state before authentication is allowed. The policy engine checks for vulnerabilities, malicious applications, and security compliance in advance. This preliminary action reduces management complexity by automating security checks while addressing vulnerability concerns through proactive policy enforcement.
3Reliability
If dedicated hardware tokens are used for authentication, then security and isolation are improved, but usability and convenience are worsened
Solution Approach 1:
The patent changes the parameters of mobile devices by implementing policy-based security evaluations and software state assessments. Instead of treating all mobile devices as inherently insecure, the system evaluates specific parameters (software vulnerabilities, security compliance, application state) to determine authentication eligibility. This parameter-based approach maintains security while enabling mobile device usability.
Data Source
AI summary
A system and method including defining at least one device authentication policy; at a policy engine, initializing authentication policy processing for an authenticator device; collecting device status assessment; evaluating policy compliance of the device status assessment to an associated defined device authentication policy; and enforcing use of the authenticator device according to the policy compliance.


