Time-Only Authentication Factors for Coordinated Multi-Factor Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems often fail to coordinate access time and authentication factors, leading to reduced security if these systems are not integrated.

Innovation Solution

Implementing a multi-factor authentication system that includes time-only, multi-session, and location-only authentication factors, which are integrated with access rules to grant resource access based on these factors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If access time and authentication factors are administered separately, then administrative flexibility is improved, but security is reduced

Engineering Contradiction:
Improveadministrative flexibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent combines separate access time administration and authentication factor administration into a unified system. The authentication policy manager integrates both functions, allowing time-based rules and authentication requirements to be coordinated through a single policy framework, thereby maintaining administrative flexibility while improving security through coordinated control.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If multiple authentication factors are required, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system dynamically determines authentication requirements based on time-of-day rules and access policies. Rather than requiring multiple authentication factors for all access scenarios, the system adaptively applies authentication factors only when necessary according to the configured policies, reducing complexity while maintaining security where needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of authentication requirement based on time and policy conditions. The system adjusts whether authentication factors are required, and which specific factors are needed, based on temporal parameters and access policies, rather than using a static multi-factor authentication approach for all cases.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If access control is based on multiple factors, then security is improved, but processing time increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary configuration of access policies and time-based rules in advance. Authentication policies are pre-defined with specific time windows and required authentication factors, allowing the authentication decision engine to quickly evaluate access requests against pre-configured rules rather than performing complex real-time policy formulation, thus reducing processing time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12381885B2Time-only based authentication factors
Publication Date: 2025.08.05 MICRO FOCUS LLC
  • US12381885B2 patent drawing
  • US12381885B2 patent drawing
  • US12381885B2 patent drawing

AI summary

A multi-factor authentication request of a user is received. For example, the multi-factor authentication request may include a valid username/password and a valid fingerprint scan. A first authentication factor of the multi-factor authentication request is an access authentication factor (e.g., the valid username/password) and a second authentication factor (e.g., the valid fingerprint scan) of the multi-factor authentication request is one of: a time-only authentication factor; a multi-session authentication factor; and a location-only authentication factor. The user is authenticated based on the first authentication factor and the second authentication factor. Access is granted to one or more resources according to one or more rules associated with the first authentication factor and second authentication factor.