Policy Engine Authenticator Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The use of mobile devices as authenticators in two-factor authentication systems poses security risks due to their vulnerable software environment, making it challenging for organizations to balance security and usability between dedicated hardware tokens and mobile devices.

Innovation Solution

A system and method that defines, evaluates, and enforces policies on computing devices to determine their suitability as authenticators by assessing their software state and potential weaknesses, using a policy engine and authenticator components to ensure the device's integrity and security before allowing its use in authentication processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If mobile devices are used as authenticators instead of hardware tokens, then usability and convenience are improved, but security and integrity are worsened

Engineering Contradiction:
ImproveusabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a policy engine as an intermediary between the mobile device and the authentication system. This policy engine evaluates the mobile device's software state, checks for vulnerabilities, and determines whether the device meets security policies before allowing authentication. This mediator enables the use of mobile devices (improving usability) while maintaining security through policy enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If mobile devices are used as authenticators, then management complexity is reduced, but vulnerability to attacks increases

Engineering Contradiction:
Improvemanagement complexityVSAvoidvulnerability to attacks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security assessments by evaluating the mobile device's software state before authentication is allowed. The policy engine checks for vulnerabilities, malicious applications, and security compliance in advance. This preliminary action reduces management complexity by automating security checks while addressing vulnerability concerns through proactive policy enforcement.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If dedicated hardware tokens are used for authentication, then security and isolation are improved, but usability and convenience are worsened

Engineering Contradiction:
ImprovesecurityVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent changes the parameters of mobile devices by implementing policy-based security evaluations and software state assessments. Instead of treating all mobile devices as inherently insecure, the system evaluates specific parameters (software vulnerabilities, security compliance, application state) to determine authentication eligibility. This parameter-based approach maintains security while enabling mobile device usability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9361451B2System and method for enforcing a policy for an authenticator device
Publication Date: 2016.06.07 CISCO TECHNOLOGY INC
  • US9361451B2 patent drawing
  • US9361451B2 patent drawing
  • US9361451B2 patent drawing

AI summary

A system and method including defining at least one device authentication policy; at a policy engine, initializing authentication policy processing for an authenticator device; collecting device status assessment; evaluating policy compliance of the device status assessment to an associated defined device authentication policy; and enforcing use of the authenticator device according to the policy compliance.