Centralized COPPA Authentication Service for Age Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online companies face challenges in verifying the age of users, particularly due to the lack of effective technological solutions, which complicates compliance with the Children's Online Privacy Protection Act (COPPA) and makes it easy for users to circumvent age verification systems.

Innovation Solution

A third-party system that allows parents or guardians to grant permissions for multiple websites and provides a one-time-authentication process for the parent-child relationship, reducing the need for individual websites to build authentication systems and manage COPPA compliance, by determining user age and authorizing access through a centralized service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If online companies query users for date of birth to verify age, then COPPA compliance is achieved, but the system can be easily circumvented by users entering false information

Engineering Contradiction:
Improveage verification reliabilityVSAvoiduser ability to circumvent
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a third-party authentication service as an intermediary between the online company and the user. This service handles the complex parent-child relationship verification and COPPA compliance checks, allowing the online company to simply query the service for authorization. The intermediary possesses specialized verification mechanisms (security questions, parental consent workflows) that prevent circumvention while maintaining ease of use for legitimate users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If online companies build their own authentication systems to verify parent-child relationships, then COPPA compliance is achieved, but the device complexity and implementation burden increase significantly

Engineering Contradiction:
ImproveCOPPA compliance assuranceVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex parent-child relationship verification functionality from the online company's system and places it in a separate third-party authentication service. The online company only needs to implement a simple query to the external service, while the service itself handles the complex workflows including security questions, parental consent collection, and relationship verification. This extraction reduces the online company's system complexity while maintaining COPPA compliance assurance.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If online companies implement comprehensive age verification for each user, then COPPA compliance is achieved, but the time and resources required for authentication increase

Engineering Contradiction:
Improveage verification accuracyVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having users authenticate with the third-party service once during initial registration. The service verifies the parent-child relationship and stores the authorization status. For subsequent visits to different online companies using the service, the verification is already complete, and only a simple authorization check is needed. This preliminary verification eliminates repeated authentication time while maintaining accurate age verification through the stored parental consent records.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8904494B2System and method to facilitate compliance with COPPA for website registration
Publication Date: 2014.12.02 AVIRA INC
  • US8904494B2 patent drawing
  • US8904494B2 patent drawing
  • US8904494B2 patent drawing

AI summary

Embodiments of the present invention provide a third-party system that allows parents or authorized guardians to continually grant permissions to several websites and online services and provides a one-time-authentication process of the parent-child relationship. Through this system, the need to re-authenticate the parent-child relationship or for each online company to build their own authentication system and COPPA record keeping mechanisms can be reduced or eliminated. In addition, the embodiments provided herein may afford a service for managing COPPA compliance that is relatively easy for online companies to integrate into their online services and websites.