Conditional Satellite Device Integration for Authentication Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication methods using one-time passcode devices and PINs are vulnerable to simultaneous theft of primary and satellite devices, undermining their effectiveness as separate authentication factors.

Innovation Solution

A processing device assesses the risk of simultaneous theft of primary and satellite devices, identifying suitable satellite devices as additional or alternative authentication factors, and integrates them into the authentication process based on determined risk, using information from these devices to authenticate users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If satellite devices are integrated as authentication factors, then authentication security is improved, but vulnerability to simultaneous theft increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsimultaneous theft risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary risk assessment by evaluating theft risk indicators before integrating satellite devices as authentication factors. This advance evaluation prevents incorporating vulnerable device combinations into the authentication process, thereby maintaining security while allowing legitimate satellite devices to be used.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication server acts as an intermediary between primary devices and satellite devices, mediating the authentication process. It assesses theft risk and conditions the integration of satellite devices based on this assessment, preventing direct vulnerability exploitation while enabling secure authentication pathways.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple authentication factors are used, then security is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system dynamically adjusts its complexity by conditionally integrating satellite devices based on assessed theft risk. When risk is low, additional authentication factors are incorporated to enhance security. When risk is high, the system reduces complexity by excluding vulnerable satellite devices, thereby adapting the authentication process to current security conditions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of authentication factor inclusion based on theft risk assessment results. By adjusting which satellite devices are integrated as authentication factors according to evaluated risk levels, the system optimizes the balance between security enhancement and operational simplicity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8850609B1Conditional integration of a satellite device into an authentication process involving a primary device
Publication Date: 2014.09.30 EMC IP HLDG CO LLC
  • US8850609B1 patent drawing
  • US8850609B1 patent drawing
  • US8850609B1 patent drawing

AI summary

A processing device comprising a processor coupled to a memory is configured to determine a risk of simultaneous theft of a primary device and at least one satellite device associated with the primary device, and to identify said at least one satellite device as an appropriate authentication factor for use in an authentication process involving the primary device, based at least in part on the determined risk. The identified satellite device may serve as an additional or alternative authentication factor relative to one or more other authentication factors. The processing device may comprise the primary device itself, or another separate device, such as an authentication server that also participates in the authentication process. Information associated with the identified satellite device is utilized in the authentication process to authenticate a user of the primary device.