Single-Channel Multi-Factor Authentication via Parallel Processing Pathways

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-factor authentication methods require multiple inputs and devices, leading to user frustration and vulnerability to forgery attacks, as they often necessitate back-and-forth communication and are not user-friendly, especially in scenarios where immediate access to multiple devices is not possible.

Innovation Solution

A single-input multi-factor authentication system that partitions user input into explicit and side channels for parallel processing, utilizing knowledge-based and non-knowledge-based authentication methods simultaneously, allowing for secure authentication without the need for multiple inputs or devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple inputs and devices are required for authentication, then security is improved, but user convenience and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple authentication factors (knowledge-based and non-knowledge-based) into a single unified authentication process that operates through one input channel. The system combines password verification with behavioral biometric analysis, voice characteristics, or typing patterns within the same authentication flow, eliminating the need for users to provide separate inputs through multiple devices while maintaining multi-factor security levels.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication system is designed to perform multiple authentication functions through a single input channel. It simultaneously evaluates knowledge-based credentials (passwords, PINs) and non-knowledge-based characteristics (behavioral patterns, biometric features) from the same user input, making the system multi-functional without requiring users to interact with multiple separate authentication mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple inputs and devices are required for authentication, then forgery attack resistance is improved, but system complexity and device requirements worsen

Engineering Contradiction:
Improveforgery attack resistanceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into distinct analytical pathways (knowledge-based authentication and non-knowledge-based authentication) that operate in parallel within a single system. This segmentation allows the system to process different authentication factors separately and combine their results, maintaining security against forgery attacks while avoiding the need for multiple separate physical devices or complex multi-device coordination.

Inventive Principle:
Principle #1Segmentation

3Reliability

If back-and-forth communication is required for authentication, then security verification is improved, but authentication time and user burden worsen

Engineering Contradiction:
Improvesecurity verificationVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary analysis of non-knowledge-based authentication factors (such as behavioral patterns, voice characteristics, or typing dynamics) simultaneously with or before the knowledge-based verification. By preparing and analyzing these factors in advance within the same authentication flow, the system eliminates the need for sequential back-and-forth communication between multiple devices, reducing authentication time while maintaining security verification.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10904246B2Single channel input multi-factor authentication via separate processing pathways
Publication Date: 2021.01.26 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10904246B2 patent drawing
  • US10904246B2 patent drawing
  • US10904246B2 patent drawing

AI summary

Mechanisms are provided to implement a single input, multi-factor authentication (SIMFA) system. The SIMFA system receives a user input for authenticating a user via a single input channel and provides the user input to first authentication logic of an explicit channel of the SIMFA system, where in the first authentication logic performs a knowledge authentication operation on the user input. The SIMFA system further provides the user input to second authentication logic of one or more side channels of the SIMFA system, where the second authentication logic performs authentication on non-knowledge-based characteristics of the user input. The SIMFA system combines results of the first authentication logic and the second authentication logic to generate a final determination of authenticity of the user. The SIMFA system generates an output indicating whether the user is an authentic user or a non-authentic user based on the final determination of authenticity of the user.