Establishing authentication persistence
Various embodiments are generally directed to performing an authentication persistence check and, based on the check, allowing a previously successful authentication to persist on a user apparatus. The check may involve a stability check on the user apparatus. If the user apparatus is stable, device fingerprinting on the apparatus may be performed, the result of which may be compared to a snapshot of apparatus taken at the time of successful authentication. If the comparison reveals changes or drifts that are within a predetermined threshold, then the persistence of the authentication is allowed.
1 . An apparatus comprising:
memory configured to store instructions;
one or more processors configured to execute the stored instructions that, when executed, cause the one or more processors to:
perform multifactor authentication, wherein one factor includes the one or more processors to establish a short-range wireless communication with a contactless card, receive data from the contactless card, send the data to a system to authenticate, and receive an indication that the contactless card is authentic;
determine a snapshot of the apparatus at a first time;
perform a stability check on the apparatus to determine that the apparatus is stable, wherein the stability check comprises a mobile network operator (MNO) verification;
perform device fingerprinting on the apparatus at a second time following a determination that the apparatus is stable;
compare the fingerprinting to the snapshot to determine whether the fingerprinting meets a predetermined requirement;
allow the multifactor authentication to persist for a predetermined time period if the fingerprinting meets the predetermined requirement; and
reauthenticate the user if the fingerprint does not meet the predetermined requirement.
2 . The apparatus of claim 1 , wherein the data is comprised in a message generated by the contactless card applying a first session key to a shared secret to generate a message access code (MAC) cryptogram and applying a second session key to the MAC cryptogram and a random number to generate the message.
3 . The apparatus of claim 1 , wherein a second factor of the multifactor authentication comprises an identifier and a password for an application, a biometric input, a passcode, or a personal identification number (PIN).
4 . The apparatus of claim 1 , wherein the snapshot comprises one or more device settings, one or more biometric inputs, or a combination thereof.
5 . The apparatus of claim 1 , wherein the fingerprint comprises one or more device settings, one or more biometric inputs, or a combination thereof.
6 . The apparatus of claim 1 , wherein the predetermined requirement is an allowed amount change between the snapshot and fingerprint.
7 . A computer-implemented method comprising:
performing multifactor authentication by an apparatus comprising a memory and one or more processors configured to execute one or more instructions stored in the memory, wherein one factor includes:
establishing, by the apparatus, a short-range wireless communication with a contactless card,
receiving, by the apparatus, data from the contactless card,
sending, by the apparatus, the data to a system to authenticate, and
receive, by the apparatus, an indication that the contactless card is authentic;
determining a snapshot of the apparatus at a first time;
performing a stability check to determine that the apparatus is stable, wherein the stability check comprises a mobile network operator (MNO) verification;
performing device fingerprinting on the apparatus at a second time following a determination that the apparatus is stable;
comparing the fingerprinting to the snapshot to determine whether the fingerprinting meets a predetermined requirement;
allowing the multifactor authentication to persist for a predetermined time period if the fingerprinting meets the predetermined requirement; and
reauthenticating the user if the fingerprint does not meet the predetermined requirement.
8 . The computer-implemented method of claim 7 , wherein the data is comprised in a message generated by the contactless card applying a first session key to a shared secret to generate a message access code (MAC) cryptogram and applying a second session key to the MAC cryptogram and a random number to generate the message.
9 . The computer-implemented method of claim 7 , wherein a second factor of the multifactor authentication comprises an identifier and a password for an application, a biometric input, a passcode, or a personal identification number (PIN).
10 . The computer-implemented method of claim 7 , wherein the snapshot comprises one or more device settings, one or more biometric inputs, or a combination thereof.
11 . The computer-implemented method of claim 7 , wherein the fingerprint comprises one or more device settings, one or more biometric inputs, or a combination thereof.
12 . The computer-implemented method of claim 7 , wherein the predetermined requirement is an allowed amount change between the snapshot and fingerprint.
13 . A non-transitory computer-readable storage medium, the computer-readable storage medium including instructions that when executed by a computer, cause the computer to:
perform multifactor authentication, wherein one factor includes:
establish a short-range wireless communication with a contactless card,
receive data from the contactless card,
send the data to a system to authenticate, and
receive an indication that the contactless card is authentic;
determine a snapshot of the apparatus at a first time;
perform a stability check to determine that the apparatus is stable, wherein the stability check comprises a mobile network operator (MNO) verification;
perform device fingerprinting on the apparatus at a second time following a determination that the apparatus is stable;
compare the fingerprinting to the snapshot to determine whether the fingerprinting meets a predetermined requirement;
allow the multifactor authentication to persist for a predetermined time period if the fingerprinting meets the predetermined requirement; and
reauthenticate the user if the fingerprint does not meet the predetermined requirement.
14 . The computer-readable storage medium of claim 13 , wherein the data is comprised in a message generated by the contactless card apply a first session key to a shared secret to generate a message access code (MAC) cryptogram and applying a second session key to the MAC cryptogram and a random number to generate the message.