Bidirectional Authentication Token for Identity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing use of digital channels for business communications between entities and users has made it difficult for users to verify the authenticity of agents, leading to vulnerabilities that fraudsters exploit, as users become complacent about sharing personal data without proper verification.
Innovation Solution
Implementing a bidirectional authentication system where users and entities can authenticate each other using a generated token, such as a code word, to verify identities, reducing the likelihood of fraudulent impersonation by ensuring only authorized agents have access to the token.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users conduct business remotely using digital channels, then convenience is improved, but security verification capability deteriorates
Solution Approach 1:
The patent introduces a token as an intermediary element that mediates between the user and the agent. The token is generated by the user's device and shared with the agent through the entity's system, serving as a verifiable proof of authentication without requiring the user to reveal personal data. This intermediary mechanism enables secure verification in remote digital interactions.
Solution Approach 2:
The system implements a feedback loop where the user's device generates a token, the entity's system receives and validates it, and then provides confirmation to both the user and the agent. This feedback mechanism ensures that both parties have verifiable proof of mutual authentication, enhancing security while maintaining remote convenience.
2Measurement precision
If users share personal data to verify agent identity, then authentication capability is improved, but vulnerability to fraud increases
Solution Approach 1:
Instead of the user verifying the agent's identity by sharing personal data, the system inverts the approach: the user's device generates a token that proves the user's identity to the agent. The agent then verifies the user's authentication status through this token, rather than the user having to verify the agent through personal data disclosure. This inversion eliminates the need for users to share sensitive information.
Solution Approach 2:
The system creates a copy of authentication proof in the form of a token that can be shared safely. Rather than sharing actual personal data, the user's device generates a token copy that contains verification information without exposing sensitive personal information. This token copy can be transmitted to the agent for verification without increasing fraud vulnerability.
3Adaptability or versatility
If agents are empowered to contact users on behalf of the entity, then service capability is improved, but risk of impersonation increases
Solution Approach 1:
The token serves as an intermediary verification mechanism between the entity's system and the agent. Before an agent can contact a user on behalf of the entity, the agent must obtain and present a valid token generated by the user's device. This intermediary token verification process ensures that only authorized agents can impersonate the entity, while still allowing empowered agents to provide services remotely.
Data Source
AI summary
Systems, methods, and other embodiments associated with bidirectional authorization are described herein. According to one embodiment, a method includes a user receiving a communication from an entity. In response to receiving the communication from the entity, the method further includes generating a token. The token may be personal identification number (PIN), alphanumeric value, code word, pass phrase, or security question. The token is received by a device of the user. Additionally, the token is transmitted to the entity. The user may then receive evidence of the token from the entity.


