Combine multiple authentication factors at random
to build a new combination for every request
For each request a subset is selected and combined from distinct factor sets — possession, device, location, knowledge and biometrics. Even for the same user the combination differs request to request, so nothing depends on a fixed credential.
No fixed credential is kept