Trusted Device-Specific Authentication via Dual Credential Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional user authentication mechanisms fail to adequately verify both user and device credentials, leading to security risks when usernames and passwords are stolen or when accessing remote devices, as they do not ensure that the correct device is being accessed.

Innovation Solution

A robust authentication mechanism that combines user credential verification with device credential verification, using a security token system where both user and device credentials are authenticated, with optional additional factors like fingerprint scans or secret questions, to ensure secure access across enterprise boundaries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional username and password authentication is used, then user credential verification is simple and quick, but security is compromised when credentials are stolen

Engineering Contradiction:
Improveauthentication simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system is segmented into two distinct components: user credential verification (username/password) and device credential verification (device ID/certificate). This segmentation allows the system to maintain simplicity for user authentication while adding a separate layer for device verification, thereby improving security without significantly complicating the user experience.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges user credential verification with device credential verification into a unified authentication process. Both the user's credentials and the device's credentials must be validated together, creating a combined authentication mechanism that enhances security while maintaining operational efficiency through integrated processing.

Inventive Principle:
Principle #5Merging (Combining)

2Productivity

If only user credentials are verified, then authentication process is fast, but device trust cannot be confirmed

Engineering Contradiction:
Improveauthentication speedVSAvoiddevice trust verification
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary device credential verification during the authentication process, checking device certificates and trust relationships before granting access. This preliminary action ensures device trust is confirmed upfront, preventing unauthorized device access while maintaining efficient authentication flow.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication provider that acts as a mediator between the user/device and the target resource. This intermediary verifies both user credentials and device credentials, issuing security tokens that confirm both aspects of authentication, thereby maintaining speed while ensuring device trust.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If device credential verification is added to user authentication, then security is enhanced, but authentication complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication provider is designed with universal functionality to handle both user credential verification and device credential verification through a single integrated process. This multi-functionality reduces the need for separate authentication systems, thereby enhancing security while limiting the increase in overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements self-service mechanisms where devices automatically present their credentials and the authentication provider automatically verifies both user and device credentials without requiring additional user actions. This self-service approach enhances security through comprehensive verification while minimizing the perceived complexity for users.

Inventive Principle:
Principle #25Self-service

4Reliability

If multiple authentication factors are required, then unauthorized access risk is reduced, but authentication time increases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements partial verification by checking device credentials to the extent necessary for security without requiring exhaustive verification of every possible factor. This approach reduces unauthorized access risk through meaningful device verification while limiting authentication time by avoiding excessive verification steps.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2283669B1Trusted device-specific authentication
Publication Date: 2020.03.04 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2283669B1 patent drawingFigure 1
  • EP2283669B1 patent drawingFigure 2
  • EP2283669B1 patent drawingFigure 3

AI summary

An authentication system combines device credential verification with user credential verification to provide a more robust authentication mechanism that is convenient to the user and effective across enterprise boundaries. In one implementation, user credential verification and device credential verification are combined to provide a convenient two-factor authentication. In this manner, an account authority service or other authentication provider verify both factors and provide a security token in accordance with the security policy of the account network resource the user is intending to access. The level of privilege granted by the target account network resource can vary depending on the number and type of factors verified by the account authority service.