Collaborative Sign-On Authentication via Cross-Session Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users' online account information is frequently compromised through phishing attacks, where malicious websites deceive users into providing credentials, leading to unauthorized access or theft.
Innovation Solution
Implementing a collaborative sign-on (CSO) process that verifies whether a user is logged into other unrelated online accounts in active sessions before allowing access to the target account, ensuring authentication credentials are correct and the user meets the necessary login requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional single-account authentication is used, then login process is simple and fast, but security is vulnerable to phishing and credential theft
Solution Approach 1:
The patent combines multiple authentication checks into a unified collaborative sign-on process. The system merges the target account's authentication request with verification of the user's login status across other unrelated accounts, creating a combined security verification mechanism that addresses the contradiction by integrating multiple security checks without requiring separate complex processes for each account.
Solution Approach 2:
The authentication system is designed with multi-functionality to serve multiple accounts simultaneously. The collaborative sign-on process universally applies the same verification logic across different account types and systems, allowing a single authentication mechanism to protect multiple accounts while maintaining consistency and simplifying the overall process.
2Reliability
If collaborative sign-on verification is implemented, then security against phishing is enhanced, but authentication time increases
Solution Approach 1:
The system performs preliminary verification by checking whether the user is logged into other accounts before completing the final authentication. This preliminary action of verifying login status across multiple accounts happens in advance, allowing the system to make informed decisions about authentication approval without requiring time-consuming real-time verification of all account states during the final login process.
Solution Approach 2:
The collaborative sign-on process incorporates feedback mechanisms where the authentication system receives status information about the user's login state from multiple accounts and uses this feedback to determine whether to approve the authentication request. This feedback loop allows the system to efficiently verify security conditions without requiring redundant authentication steps, thereby reducing overall authentication time while maintaining enhanced security.
Data Source
AI summary
An authentication approval request can be received by a first system from a second system. The first system can determine whether the user is required to be logged into at least a second online account hosted by at least a third system unrelated to the second system in order to approve the authentication request. If the user is required to be logged into at least the second online account in order to approve the authentication request, the first system can determine whether the user presently is logged into at least the second online account in at least one presently active user session. If the user presently is logged into at least the second online account in at least one presently active user session, the first system can communicate to the second system a response indicating that the user is approved for authentication with the second system.


