Dynamic Proximity Authentication for Secure Device Sessions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy security techniques are inadequate for modern cloud-based environments, as they rely on outdated perimeters, are costly, complex, and vulnerable to security threats, particularly due to reliance on passwords and lack of proximity confirmation between users and computing devices, leading to inefficiencies and increased risk of unauthorized access.

Innovation Solution

Implement a system that dynamically monitors and manages proximity between securely communicating devices, using real-time data from various sensors to authenticate users through concurrent verification of their presence and physical proximity, allowing for automatic session control actions and secure access to resources without the need for traditional authentication methods like passwords.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If traditional perimeter-based security techniques are used, then security control is simplified, but security effectiveness deteriorates in modern cloud-based environments

Engineering Contradiction:
Improvesecurity control complexityVSAvoidsecurity effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements dynamic session control that automatically adjusts security measures based on real-time proximity detection. The system transitions from static perimeter-based security to dynamic context-aware security, where session termination or continuation is automatically determined based on whether the user device remains within the proximity threshold of the endpoint device.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent replaces traditional mechanical/perimeter-based security controls with sensor-based proximity detection systems. Instead of relying on network firewalls and perimeter defenses, the system uses sensors (camera, microphone, GPS, accelerometer) to detect physical proximity and substitute physical presence verification for traditional authentication mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If biometric authentication alone is used, then user convenience is improved, but security vulnerability increases due to duplication attacks

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges biometric authentication with proximity detection technology. The system requires both biometric verification and physical proximity confirmation through sensor data (camera capturing user face, microphone detecting voice, GPS confirming location). This combination creates multiple authentication factors that must be satisfied simultaneously, preventing attacks that duplicate only biometric data.

Inventive Principle:
Principle #5Merging (Combining)

3Device complexity

If passwords are used for authentication, then security management is simplified, but security strength deteriorates due to theft and duplication

Engineering Contradiction:
Improvesecurity management complexityVSAvoidsecurity strength
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent substitutes password-based authentication with sensor-based proximity verification. Instead of relying on secret knowledge (passwords) that can be stolen or duplicated, the system uses physical sensor data (camera images, audio recordings, location information) that inherently verify the user's actual physical presence near the endpoint device, making theft and duplication attacks ineffective.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If users are required to maintain network connection for secure access, then security control is improved, but productivity deteriorates due to access limitations

Engineering Contradiction:
Improvesecurity controlVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic session management that adapts security requirements based on real-time proximity verification. When the system detects that the user device remains within the defined proximity threshold of the endpoint device through sensor monitoring, it maintains secure session access even without continuous network connection, automatically terminating sessions only when proximity is lost.

Inventive Principle:
Principle #15Dynamics

5Measurement precision

If proximity monitoring is continuously performed, then security detection precision is improved, but energy consumption increases

Engineering Contradiction:
Improveproximity detection precisionVSAvoidenergy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent implements periodic proximity monitoring instead of continuous monitoring. The system checks proximity status at defined intervals using sensor data, maintaining security oversight while allowing the device to enter low-power states between monitoring cycles. This periodic approach balances detection precision with energy conservation.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10749876B2Adaptive and dynamic access control techniques for securely communicating devices
Publication Date: 2020.08.18 CYBER ARK SOFTWARE LTD
  • US10749876B2 patent drawing
  • US10749876B2 patent drawing
  • US10749876B2 patent drawing

AI summary

Disclosed embodiments relate to adaptively and dynamically monitoring and managing a proximity status between securely communicating devices. Techniques include identifying a secure connection session established between an endpoint computing resource and an auxiliary computing device associated with a user; receiving real-time proximity data associated with at least one of the user or the auxiliary computing device; receiving proximity data associated with the endpoint computing resource; determining, based on the real-time proximity data associated with at least one of the user or the auxiliary computing device and the proximity data associated with the endpoint computing resource, whether at least one of the auxiliary computing device or the user has left the proximity to the endpoint computing resource; and implementing, based on the determining, an automatic session control action for the secure connection session.