Device-to-Device Push Approval for Passwordless MFA Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods rely on cumbersome passwords, which can lead to security issues due to easy-to-remember passwords, repetitive use, and forgotten credentials, complicating access management and increasing the risk of unauthorized access.
Innovation Solution
A method that utilizes a communication link between endpoint devices to facilitate multi-factor authentication, where a first endpoint device, not registered for real-time verification, leverages a second registered endpoint device to receive and relay authentication prompts through a communication link, allowing unified access and reducing the need for separate devices in the authentication process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If passwords are used for authentication, then access control is implemented, but security issues arise due to easy-to-remember passwords, repetitive use, and forgotten credentials
Solution Approach 1:
The patent introduces a communication link as an intermediary between two endpoint devices to transfer authentication decisions. Instead of relying on passwords, the system uses a trusted communication channel (e.g., Bluetooth, NFC, or QR code) between devices to convey authentication approval, eliminating the need for users to manage passwords while maintaining security through device-to-device verification
Solution Approach 2:
The patent replaces the mechanical/password-based authentication system with a communication-based system. Instead of typing passwords or using physical tokens, the authentication process is substituted with electronic message passing between devices through a communication link, transforming the authentication mechanism from manual input to automated digital verification
2Reliability
If a first endpoint device not registered for real-time verification attempts authentication, then access is restricted, but user convenience is reduced requiring separate registered devices
Solution Approach 1:
The patent enables endpoint devices to serve multiple functions: they can be used for both resource access and authentication verification without requiring separate registered devices. The communication link allows any endpoint device to leverage another endpoint device's registration status, making the authentication system universally applicable across all user devices rather than requiring device-specific registration
3Reliability
If multi-factor authentication with separate devices is implemented, then security is strengthened, but device complexity and operational steps increase
Solution Approach 1:
The patent merges the authentication verification process into the existing communication infrastructure between endpoint devices. Instead of adding separate authentication devices or complex systems, it combines the authentication decision transfer with the normal device-to-device communication channel, simplifying the overall system architecture while maintaining multi-factor authentication security
Data Source
AI summary
In one embodiment, a method, by an authentication server, includes receiving user information associated with a first authentication factor for verification from the first endpoint device. The method further includes in response to verifying the first authentication factor, transmitting a prompt to provide an authentication decision associated with a second authentication factor to the second endpoint device, wherein the second endpoint device is communicatively coupled to the first endpoint device through the communication link. The method further includes receiving the authentication decision that is initiated by the first endpoint device from the second endpoint device, wherein the first endpoint device is configured to initiate and transmit the authentication decision to the second endpoint device in response to receiving the second authentication factor from the second endpoint device.


