RPA Bot MFA Token Relay for Secure Automated Login

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Robotic process automation (RPA) bots are unable to implement multi-factor authentication (MFA) or two-factor authentication (2FA) due to the requirement of human interaction, which increases security risks in automated processes and limits their ability to access secure systems.

Innovation Solution

A method where a task-executing bot automatically acquires a time-dependent MFA security token from a pre-authenticated security bot, allowing the bot to authenticate and access secure systems without human intervention, by establishing a secure session using a code generating algorithm and a secondary device-like security bot.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional single-factor authentication is used for RPA bots, then automation efficiency and productivity are maintained, but security reliability deteriorates due to lack of MFA/2FA protection

Engineering Contradiction:
ImprovesecurityVSAvoidautomation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The RPA bot autonomously performs MFA authentication without human intervention by automatically acquiring tokens from the code generating algorithm and submitting them to the authentication server, enabling the bot to serve itself in the authentication process while maintaining both security and productivity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A code generating algorithm acts as an intermediary between the RPA bot and the authentication server, providing time-dependent security tokens that enable automated authentication while maintaining MFA security requirements

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If MFA/2FA with human interaction is required, then security reliability is improved, but automation capability deteriorates due to inability of bots to perform manual authentication

Engineering Contradiction:
ImprovesecurityVSAvoidautomation capability
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The RPA bot autonomously performs the complete MFA authentication process by automatically acquiring tokens from the code generating algorithm and submitting them to the authentication server, eliminating the need for human interaction while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical process of human interaction for MFA authentication is replaced by an automated electronic system where the RPA bot communicates with the code generating algorithm and authentication server through automated token acquisition and submission

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If frequent password changes are required for security, then security reliability is improved, but ease of operation deteriorates due to user inconvenience

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The manual password change process is replaced by automated token-based authentication where the RPA bot automatically acquires time-dependent tokens from the code generating algorithm, eliminating the need for users to manually change passwords while maintaining strong security

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12003503B2Multi-factor authentication system and method
Publication Date: 2024.06.04 MASCH TWO LTD
  • US12003503B2 patent drawing

AI summary

Multi-factor authentication (MFA) on a computer configured for robotic process automation (RPA) using task-executing bot(s) includes, responsive to a log-in request from the task-executing bot to a gatekeeping first server, at the task-executing bot, responsive to receiving an MFA challenge from the first server, acquiring a time-dependent MFA security token from a code generating algorithm associated with a pre-authenticated security bot perceived by the first server to be at a different address than the task-executing bot, the security bot having undergone a one-time synchronization at set-up to support RPA during which an association is established between the security and task-executing bots such that the association validates the security bot as a secondary device within MFA to automate subsequent MFA and inserting the time-dependent MFA security token into a reply to the MFA challenge and sending the reply to the first server.