Multi-Factor Authentication System with Risk-Based Token Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Single-factor authentication technologies are inadequate in preventing sophisticated hacking threats, leading to increased risks of information leakage, necessitating a more robust multi-factor authentication approach.

Innovation Solution

An authentication service system and method that employs a sequence of authentication processes using different factors (knowledge-based, possession-based, and feature-based) and generates access tokens, with risk scoring to determine additional authentication requirements, thereby enhancing security through multi-factor authentication and risk analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If single-factor authentication technology is used, then authentication process is simple and fast, but security against sophisticated hacking threats is insufficient

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidsecurity against hacking threats
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into multiple independent factors (knowledge-based, possession-based, and feature-based authentication). Each factor represents a separate authentication segment that must be completed sequentially, allowing the system to maintain simplicity at each stage while achieving high security through the combination of multiple segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges three different types of authentication factors (knowledge-based, possession-based, and feature-based) into a unified multi-factor authentication process. This combination resolves the contradiction by integrating the simplicity of individual authentication methods with the security enhancement provided by their collective application.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If multi-factor authentication is implemented, then security against hacking threats is improved, but authentication process complexity increases

Engineering Contradiction:
Improvesecurity against hacking threatsVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process dynamically adjusts the number and type of factors required based on risk assessment. The system evaluates risk scores and authentication results in real-time, making the authentication process adaptive rather than static. This allows the system to maintain high security when needed while reducing complexity when risk is low.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where authentication results and risk scores are continuously evaluated to determine whether additional authentication factors are required. This feedback loop allows the system to optimize the authentication process complexity based on actual security needs rather than applying maximum security measures uniformly.

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple authentication factors are required, then authentication security is enhanced, but authentication time increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies partial authentication action by requiring only the necessary number of authentication factors based on risk assessment. When risk scores indicate lower threat levels, the system accepts fewer authentication factors, reducing authentication time while maintaining adequate security. This partial action approach prevents unnecessary time consumption when maximum security is not required.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10673843B2System and method for authentication service
Publication Date: 2020.06.02 SAMSUNG SDS CO LTD
  • US10673843B2 patent drawing
  • US10673843B2 patent drawing
  • US10673843B2 patent drawing

AI summary

Provided is an authentication service system and authentication service method. According to embodiments of the present disclosure, when a plurality of authentication processes are performed using different authentication factors, an access token is issued based on an authentication factor used in a previous authentication process; and a subsequent authentication process is performed according to validity of the access token issued in the previous authentication process.