Proxy Device Multifactor Authentication for Mail Server Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing email protocols such as POP3 and IMAP lack robust security measures to prevent unauthorized access, as they do not include provisions for inspecting and deterring unauthorized use of passwords and account data.

Innovation Solution

A proxy device is introduced to evaluate and enforce security requirements for email access requests from client devices, which may involve additional authentication steps using authentication devices that utilize multifactor authentication, including user credentials, biometrics, and geographic location verification, before allowing access to the email server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If email protocols are kept simple for efficient access, then bandwidth usage and server-side processing are minimized, but security measures to prevent unauthorized access are insufficient

Engineering Contradiction:
Improveemail access efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

A proxy device is introduced as an intermediary between the client device and email server. The proxy evaluates email access requests and enforces security requirements without requiring changes to the simple email protocols themselves, thus maintaining efficiency while adding security through the intermediary layer

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If additional authentication steps are implemented, then security against unauthorized access is improved, but device complexity and authentication process time increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system dynamically adjusts the authentication process based on risk assessment. The proxy device evaluates requests and determines the appropriate level of authentication required, using multifactor authentication only when necessary rather than requiring all users to go through complex authentication processes always

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication system is segmented into multiple independent factors (password, biometrics, geographic location). Each factor can be evaluated separately, and the system can selectively apply different authentication factors based on the specific request and risk level, rather than requiring all factors for every authentication

Inventive Principle:
Principle #1Segmentation

3Reliability

If multifactor authentication is enforced, then unauthorized access is deterred, but processing time and user operation complexity increase

Engineering Contradiction:
Improveaccess authorizationVSAvoidauthentication process ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adapts the authentication process to the user's context and risk profile. For low-risk requests from recognized devices and locations, the process remains simple. For suspicious or high-risk requests, additional authentication factors are selectively enforced, optimizing both security and ease of operation

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9787678B2Multifactor authentication for mail server access
Publication Date: 2017.10.10 VERIZON PATENT & LICENSING INC
  • US9787678B2 patent drawing
  • US9787678B2 patent drawing
  • US9787678B2 patent drawing

AI summary

A proxy device intercepts requests from client devices to access message data through a message data device, such as accessing e-mail messages through a mail server implementing post office protocol (POP) or other messaging protocol. The proxy device determines to authenticate of a client device when, for example, the client device, is located within certain areas that differ from a geographic region associated with a message account holder. Authentication of the client device may include collecting additional information, such as a universal identifier that may be used by the client device to access various services. The proxy device may further forward a notification message to the client device indicating the access to the message data is pending until the client device is authenticated. If the client device is successfully authenticated, the proxy device forwards the request to the message data device to enable the client device to access the message data.