Trusted Device Location Authentication Update

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication systems for computer services face challenges in providing a seamless user experience when users access services from unfamiliar locations, often requiring additional authentication or denying access, which can disrupt the user experience and increase security risks.

Innovation Solution

The authentication process utilizes synchronization relationships between devices and services to update familiar locations, allowing trusted devices to authenticate users even in new locations, thereby enhancing user experience and security by integrating location-based authentication with device relationships.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If location-based authentication is used to verify user authenticity, then security is improved, but user experience deteriorates when users access services from unfamiliar locations

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication actions by establishing synchronization relationships between devices and services during familiar location visits. This pre-established relationship allows the system to quickly verify device trustworthiness during subsequent authentication attempts, avoiding the need for challenging authentication procedures when users visit unfamiliar locations with trusted devices.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a device synchronization relationship as an intermediary mechanism between location-based authentication and user access. This intermediary allows the system to indirectly verify user authenticity through device-trust relationships, bypassing the need for direct location verification and eliminating the trade-off between security and user experience.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If additional authentication information is required for unfamiliar locations, then security is improved, but access time increases

Engineering Contradiction:
ImprovesecurityVSAvoidaccess time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication by establishing device synchronization relationships during initial visits to locations. When users later access services from unfamiliar locations, the pre-established device relationships enable rapid verification, eliminating the need for time-consuming additional authentication procedures.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If access is denied for unfamiliar locations, then security is improved, but adaptability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidaccess flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adjusts authentication requirements based on device-trust relationships. Instead of applying static location-based access control, the system adapts authentication behavior by recognizing trusted devices through synchronization relationships, allowing users to access services from any location with their trusted devices while maintaining security.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9449156B2Using trusted devices to augment location-based account protection
Publication Date: 2016.09.20 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9449156B2 patent drawing
  • US9449156B2 patent drawing
  • US9449156B2 patent drawing

AI summary

An authentication process receives information identifying a user, a device used by the user and a location in which the device is being used. That authentication process determines whether the location is among a set of familiar locations stored about the user for a service being accessed. If the location is not among the set of familiar locations, then the user is not authenticated. A desirable user experience can be obtained by using information about any existing relationship, such as a synchronization relationship, between the device and the service established at a prior familiar location. Instead of challenging a user whose device is in an unfamiliar location, the authentication process determines whether the device has a relationship established with the service. If the device has a relationship established with the service, then the set of familiar locations is updated to include the location in which the device is being used.