Touch-Free Multi-Factor Authentication via Secure Proximity Channel
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods, especially in multi-factor scenarios, are cumbersome and prone to theft, requiring users to remember and provide multiple credentials across different devices, which can be insecure and inconvenient.
Innovation Solution
A touch-free multi-factor authentication system where a mobile computing device, when in proximity to an authentication computing device, establishes a secure communication channel to transmit and receive encrypted credentials, eliminating the need for physical interaction and simplifying the authentication process by using a combination of text-based and biometric factors stored securely within trusted execution environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional multi-factor authentication methods are used (requiring multiple credentials), then security is improved, but ease of operation deteriorates due to the burden of remembering and providing multiple credentials across different devices
Solution Approach 1:
The patent combines multiple authentication factors (biometric data, device identifiers, cryptographic keys) into a single integrated authentication system. The mobile computing device consolidates these multiple credentials and presents them as a unified authentication package to the authentication computing device, eliminating the need for users to manually manage separate credentials for each factor.
Solution Approach 2:
The system enables automatic authentication where the mobile computing device automatically presents the required credentials to the authentication computing device without requiring user intervention to manually input multiple credentials. The biometric authentication and credential presentation occur automatically through the established communication channel, making the system serve itself rather than requiring active user management of multiple credentials.
2Reliability
If multiple credentials are required for authentication, then security is improved, but device complexity increases due to the need to manage and transmit multiple credentials across devices
Solution Approach 1:
The mobile computing device acts as an intermediary that holds and manages multiple credentials securely, then presents them as a unified package to the authentication computing device. This intermediary approach simplifies the authentication process by centralizing credential management in one device rather than requiring complex coordination between multiple devices and credential systems.
Solution Approach 2:
The authentication system is segmented into distinct functional components: biometric data collection, device identifier generation, cryptographic key management, and credential presentation. Each component operates independently but contributes to the overall authentication process, allowing the system to manage multiple credentials through modular, manageable segments rather than as a monolithic complex system.
3Ease of operation
If touch-free authentication is implemented, then ease of operation is improved, but reliability may deteriorate due to potential security concerns with wireless transmission
Solution Approach 1:
The patent replaces physical contact-based authentication (touching devices, inserting cards) with wireless communication-based authentication. The mobile computing device establishes a wireless communication channel with the authentication computing device to transmit credentials without physical contact, substituting mechanical interaction with electromagnetic communication while maintaining security through encrypted transmission.
Solution Approach 2:
The system changes the transmission parameter from physical contact to wireless electromagnetic signals. By altering the medium of credential transmission from mechanical contact to electromagnetic waves, the system achieves touch-free operation while compensating for potential security concerns through cryptographic encryption and secure communication protocols.
Data Source
AI summary
Technologies for authenticating a user and a mobile computing device of the user at an authentication computing device include generating, at the authentication computing device, a multi-factor authentication credential that includes a text-based credential and a plurality of biometric authentication factors corresponding to the user. The mobile computing device is configured to detect whether the authentication computing device is within proximity of the mobile computing device and establish a secure communication channel therebetween. The mobile computing device is further configured to securely store the multi-factor authentication credential received from the authentication computing device. The authentication computing device is configured to receive the multi-factor authentication credential from the mobile computing device and analyze the received multi-factor authentication credential to determine whether the user is an authorized user of the authentication computing device and take an action based on a result of the analysis. Other embodiments are described and claimed.


