Bidirectional Trust Authentication via Sequence Code Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional authentication methods, such as one-time password (OTP) challenges, are one-sided and do not establish mutual trust, making users vulnerable to fraudulent activities like phishing and impersonation. These methods also fail to verify granular actions performed on user accounts.

Innovation Solution

The system establishes bi-directional trust between client and agent users by creating a communication channel for authentication sequence codes. The primary device determines an authentication sequence code, which is then provided to the recipient device. The recipient device generates a candidate authentication sequence code message, which is verified by the system device, updating the verification status and providing a shared trust decision message.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional one-sided authentication methods are used, then user identity verification is achieved, but mutual trust is not established and users remain vulnerable to fraudulent activities

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidfraudulent activity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent inverts the traditional authentication model by having the agent verify the user's identity through code comparison, while simultaneously having the user verify the agent's identity through the same mechanism. This bidirectional verification establishes mutual trust and prevents both phishing attacks (where fraudsters impersonate agents) and unauthorized access attempts.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces an authentication sequence code as an intermediary element that mediates the verification process between user and agent. The code serves as a shared secret that both parties independently verify, creating a trusted communication channel without requiring direct trust between the user and agent.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional broad verification methods are used, then general account access is secured, but granular action verification is not performed

Engineering Contradiction:
Improveaccount access securityVSAvoidgranular action verification capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the authentication process into distinct verification stages: initial account access verification, communication channel establishment, and granular action verification. Each stage uses the authentication sequence code mechanism to verify specific actions, allowing fine-grained control over what actions are authorized and tracked.

Inventive Principle:
Principle #1Segmentation

3Reliability

If unidirectional trust is established, then user authentication is confirmed, but agent identity assurance is not provided

Engineering Contradiction:
Improveuser authentication accuracyVSAvoidagent identity information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent inverts the traditional authentication model by having the agent verify the user's identity through code comparison, while simultaneously having the user verify the agent's identity through the same mechanism. This bidirectional verification establishes mutual trust and prevents both phishing attacks (where fraudsters impersonate agents) and unauthorized access attempts.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS20250119294A1Systems and methods for establishing shared trust between a primary client user and recipient agent user
Publication Date: 2025.04.10 WELLS FARGO BANK NA
  • US20250119294A1 patent drawing
  • US20250119294A1 patent drawing
  • US20250119294A1 patent drawing

AI summary

Systems, apparatuses, methods, and computer program products are disclosed for establishing shared trust between a client user and an agent user for a current communication. An example method includes providing a logon request for a client user account associated with a client user to a system device. The example method further includes determining an authentication sequence code using the mobile application in an instance in which the logon request was successfully authenticated and causing the authentication sequence code to be provided to the agent device associated with the agent user. The example method further includes receiving a shared trust decision message from the system device, wherein the shared trust decision message is indicative of a verification status for the current communication.