Device-to-Device Push Approval for Passwordless MFA Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods rely on cumbersome passwords, which can lead to security issues due to easy-to-remember passwords, repetitive use, and forgotten credentials, complicating access management and increasing the risk of unauthorized access.

Innovation Solution

A method that utilizes a communication link between endpoint devices to facilitate multi-factor authentication, where a first endpoint device, not registered for real-time verification, leverages a second registered endpoint device to receive and relay authentication prompts through a communication link, allowing unified access and reducing the need for separate devices in the authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If passwords are used for authentication, then access control is implemented, but security issues arise due to easy-to-remember passwords, repetitive use, and forgotten credentials

Engineering Contradiction:
Improveauthentication securityVSAvoidpassword management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a communication link as an intermediary between two endpoint devices to transfer authentication decisions. Instead of relying on passwords, the system uses a trusted communication channel (e.g., Bluetooth, NFC, or QR code) between devices to convey authentication approval, eliminating the need for users to manage passwords while maintaining security through device-to-device verification

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/password-based authentication system with a communication-based system. Instead of typing passwords or using physical tokens, the authentication process is substituted with electronic message passing between devices through a communication link, transforming the authentication mechanism from manual input to automated digital verification

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If a first endpoint device not registered for real-time verification attempts authentication, then access is restricted, but user convenience is reduced requiring separate registered devices

Engineering Contradiction:
Improveauthentication verificationVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables endpoint devices to serve multiple functions: they can be used for both resource access and authentication verification without requiring separate registered devices. The communication link allows any endpoint device to leverage another endpoint device's registration status, making the authentication system universally applicable across all user devices rather than requiring device-specific registration

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If multi-factor authentication with separate devices is implemented, then security is strengthened, but device complexity and operational steps increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication verification process into the existing communication infrastructure between endpoint devices. Instead of adding separate authentication devices or complex systems, it combines the authentication decision transfer with the normal device-to-device communication channel, simplifying the overall system architecture while maintaining multi-factor authentication security

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12489748B2Device to device binding for push approval
Publication Date: 2025.12.02 CISCO TECHNOLOGY INC
  • US12489748B2 patent drawing
  • US12489748B2 patent drawing
  • US12489748B2 patent drawing

AI summary

In one embodiment, a method, by an authentication server, includes receiving user information associated with a first authentication factor for verification from the first endpoint device. The method further includes in response to verifying the first authentication factor, transmitting a prompt to provide an authentication decision associated with a second authentication factor to the second endpoint device, wherein the second endpoint device is communicatively coupled to the first endpoint device through the communication link. The method further includes receiving the authentication decision that is initiated by the first endpoint device from the second endpoint device, wherein the first endpoint device is configured to initiate and transmit the authentication decision to the second endpoint device in response to receiving the second authentication factor from the second endpoint device.