Anti-Authentication Credentials for Coerced Device Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern devices and digital accounts are vulnerable to unauthorized access, leading to potential data inspection and appropriation, as users are increasingly compelled to provide access to third parties, necessitating new methods for mitigating unauthorized access and controlling access to computing resources.
Innovation Solution
A remote computer security service that includes an anti-authentication application instance, which identifies anti-authentication actions and automatically alters the device or account to a protected state by encrypting or deleting sensitive data using asymmetric key cryptography, even without network connectivity, using distinct anti-authentication credentials that differ from standard authentication credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If standard authentication credentials are used to provide access to computing resources, then ease of operation is improved, but security against unauthorized access deteriorates when users are coerced
Solution Approach 1:
The system applies preliminary anti-action by implementing anti-authentication credentials that trigger protective actions before actual unauthorized access occurs. When coercion is detected through the anti-authentication credential input, the system preemptively alters the computing device state to protect sensitive data, rather than waiting for damage to occur
Solution Approach 2:
The system inverts the traditional authentication model by introducing anti-authentication credentials that work opposite to standard authentication. Instead of credentials that grant access, these credentials trigger actions that protect against access by altering the device state, effectively inverting the purpose of credential-based access control
2Reliability
If anti-authentication protective services alter the computing device to a protected state, then security is improved, but ease of operation deteriorates due to restricted access
Solution Approach 1:
The system implements dynamics by making the computing device state changeable between normal and protected states based on credential input. The device dynamically adapts its accessibility and functionality depending on whether anti-authentication credentials are provided, allowing flexible adjustment of security levels without permanent restrictions
Solution Approach 2:
The system applies parameter changes by modifying the operational parameters of the computing device when transitioning to protected state. Functions are disabled, data is encrypted or deleted, and device characteristics change based on the anti-authentication policy, effectively altering the device's operational parameters to enhance security
3Reliability
If sensitive data is encrypted or deleted to protect against unauthorized access, then security is improved, but loss of information occurs
Solution Approach 1:
The system applies local quality by selectively applying protective actions to specific sensitive data or device functions rather than uniformly affecting all data. The anti-authentication policy identifies particular data elements or functions to protect, allowing targeted protection while preserving other non-sensitive information and functionality
4Reliability
If the computing device is altered to a protected state, then security against compelled access is improved, but device functionality deteriorates
Solution Approach 1:
The system implements partial action by applying protective measures only to the extent necessary to prevent unauthorized access. Rather than completely disabling all device functions, the system selectively alters specific functions or data elements based on the anti-authentication policy, applying just enough protection without excessive functional loss
Data Source
AI summary
A system and method of securing a computing device with a remote computer security service includes: identifying a computing device that is subscribed to a remote computer security service, wherein the computing device comprises an anti-authentication application instance provided by the remote computer security service based on the subscription; identifying an occurrence of an anti-authentication action involving the computing device based on anti-authentication policy set to a subscriber anti-authentication account with the remote computer security service for the computing device; responsively to the anti-authentication action, automatically performing by the remote security service or the anti-authentication application instance one or more anti-authentication protective services by protectively altering the computing device based on the anti-authentication policy, wherein the computing device is altered to a protected state from a normal state based on the performance of the one or more anti-authentication protective services.


