Bidirectional Trust Authentication via Sequence Code Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional authentication methods, such as one-time password (OTP) challenges, are one-sided and do not establish mutual trust, making users vulnerable to fraudulent activities like phishing and impersonation. These methods also fail to verify granular actions performed on user accounts.
Innovation Solution
The system establishes bi-directional trust between client and agent users by creating a communication channel for authentication sequence codes. The primary device determines an authentication sequence code, which is then provided to the recipient device. The recipient device generates a candidate authentication sequence code message, which is verified by the system device, updating the verification status and providing a shared trust decision message.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional one-sided authentication methods are used, then user identity verification is achieved, but mutual trust is not established and users remain vulnerable to fraudulent activities
Solution Approach 1:
The patent inverts the traditional authentication model by having the agent verify the user's identity through code comparison, while simultaneously having the user verify the agent's identity through the same mechanism. This bidirectional verification establishes mutual trust and prevents both phishing attacks (where fraudsters impersonate agents) and unauthorized access attempts.
Solution Approach 2:
The patent introduces an authentication sequence code as an intermediary element that mediates the verification process between user and agent. The code serves as a shared secret that both parties independently verify, creating a trusted communication channel without requiring direct trust between the user and agent.
2Reliability
If traditional broad verification methods are used, then general account access is secured, but granular action verification is not performed
Solution Approach 1:
The patent segments the authentication process into distinct verification stages: initial account access verification, communication channel establishment, and granular action verification. Each stage uses the authentication sequence code mechanism to verify specific actions, allowing fine-grained control over what actions are authorized and tracked.
3Reliability
If unidirectional trust is established, then user authentication is confirmed, but agent identity assurance is not provided
Solution Approach 1:
The patent inverts the traditional authentication model by having the agent verify the user's identity through code comparison, while simultaneously having the user verify the agent's identity through the same mechanism. This bidirectional verification establishes mutual trust and prevents both phishing attacks (where fraudsters impersonate agents) and unauthorized access attempts.
Data Source
AI summary
Systems, apparatuses, methods, and computer program products are disclosed for establishing shared trust between a client user and an agent user for a current communication. An example method includes providing a logon request for a client user account associated with a client user to a system device. The example method further includes determining an authentication sequence code using the mobile application in an instance in which the logon request was successfully authenticated and causing the authentication sequence code to be provided to the agent device associated with the agent user. The example method further includes receiving a shared trust decision message from the system device, wherein the shared trust decision message is indicative of a verification status for the current communication.


