Conditional Satellite Device Integration for Authentication Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication methods using one-time passcode devices and PINs are vulnerable to simultaneous theft of primary and satellite devices, undermining their effectiveness as separate authentication factors.
Innovation Solution
A processing device assesses the risk of simultaneous theft of primary and satellite devices, identifying suitable satellite devices as additional or alternative authentication factors, and integrates them into the authentication process based on determined risk, using information from these devices to authenticate users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If satellite devices are integrated as authentication factors, then authentication security is improved, but vulnerability to simultaneous theft increases
Solution Approach 1:
The system performs preliminary risk assessment by evaluating theft risk indicators before integrating satellite devices as authentication factors. This advance evaluation prevents incorporating vulnerable device combinations into the authentication process, thereby maintaining security while allowing legitimate satellite devices to be used.
Solution Approach 2:
The authentication server acts as an intermediary between primary devices and satellite devices, mediating the authentication process. It assesses theft risk and conditions the integration of satellite devices based on this assessment, preventing direct vulnerability exploitation while enabling secure authentication pathways.
2Reliability
If multiple authentication factors are used, then security is improved, but system complexity increases
Solution Approach 1:
The authentication system dynamically adjusts its complexity by conditionally integrating satellite devices based on assessed theft risk. When risk is low, additional authentication factors are incorporated to enhance security. When risk is high, the system reduces complexity by excluding vulnerable satellite devices, thereby adapting the authentication process to current security conditions.
Solution Approach 2:
The system changes the parameter of authentication factor inclusion based on theft risk assessment results. By adjusting which satellite devices are integrated as authentication factors according to evaluated risk levels, the system optimizes the balance between security enhancement and operational simplicity.
Data Source
AI summary
A processing device comprising a processor coupled to a memory is configured to determine a risk of simultaneous theft of a primary device and at least one satellite device associated with the primary device, and to identify said at least one satellite device as an appropriate authentication factor for use in an authentication process involving the primary device, based at least in part on the determined risk. The identified satellite device may serve as an additional or alternative authentication factor relative to one or more other authentication factors. The processing device may comprise the primary device itself, or another separate device, such as an authentication server that also participates in the authentication process. Information associated with the identified satellite device is utilized in the authentication process to authenticate a user of the primary device.


