Identity Provider Zero-Touch MFA Through Trusted App Sessions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user authentication methods, particularly in a hybrid device environment, are burdensome due to frequent context-switching and disruptions caused by multifactor authentication (MFA) prompts, especially when transitioning across devices.
Innovation Solution
A zero-touch MFA system using trusted multimedia sources, where an identity provider (IDP) leverages pre-established trust relationships with user devices and applications to perform seamless biometric authentication without user intervention, utilizing biometric sensors integrated with collaboration services like video conferencing endpoints.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multifactor authentication (MFA) is implemented with frequent authentication prompts, then security is improved, but user burden and context-switching increase
Solution Approach 1:
The system performs biometric authentication in advance by capturing biometric data (face, voice, fingerprint) during normal application usage and storing it for later verification. This preliminary action eliminates the need for users to perform authentication actions at the moment of access requests, thereby maintaining security while reducing user burden and context-switching.
Solution Approach 2:
The system enables self-service authentication where the user's own biometric characteristics serve as the authentication credential. The biometric sensor automatically captures and verifies the user's identity without requiring manual intervention, code entry, or switching to another device, thus improving ease of operation while maintaining security.
2Reliability
If multifactor authentication (MFA) is implemented with device switching, then security is improved, but productivity and user experience deteriorate
Solution Approach 1:
The system introduces an intermediary biometric authentication mechanism that operates within the primary application interface. Instead of requiring users to switch to a secondary device for authentication, the biometric sensor acts as an intermediary that verifies identity seamlessly within the current application context, thereby maintaining security without disrupting workflow or reducing productivity.
Solution Approach 2:
The system merges the authentication function with the primary application interface by integrating biometric sensors directly into the application environment. This combining of authentication and application usage into a single seamless flow eliminates the need for device switching and maintains user focus on productivity tasks while ensuring secure access.
3Reliability
If traditional MFA prompts are used, then authentication control is maintained, but user fatigue and disruption increase
Solution Approach 1:
The system replaces mechanical authentication methods (typing codes, pressing buttons, switching devices) with automated biometric verification. Biometric sensors automatically capture and verify user identity characteristics without requiring physical manipulation or conscious user effort, thereby maintaining authentication control while eliminating user fatigue and disruption associated with traditional MFA prompts.
Data Source
AI summary
A method comprises: at an identity provider, upon receiving a request for authentication of a user to a target application that is hosted on a user device and into which the user has logged-in: identifying one or more biometric tests to be applied to the user to satisfy the request; selecting, from a list of application services that have trust relationships with the identity provider, an application service which has an active session with the user and supports the one or more biometric tests; requesting the application service to perform multifactor authentication that includes the one or more biometric tests; receiving, from the application service, biometric test results that indicate whether each of the one or more biometric tests passed or failed; and determining that the authentication has passed or failed based on the biometric test results.


