Credential Recovery via Trusted Entity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication systems require physical possession of an authentication token or credential, causing issues when the token is misplaced, lost, or unavailable, and do not facilitate recovery without it.

Innovation Solution

A computer-implemented method and system that allows credential recovery by determining a policy requiring verification from trusted entities, where the authentication server confirms the identity of the user through these entities, enabling recovery of credentials without the need for physical possession of the token.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional authentication systems require physical possession of an authentication token, then security is maintained, but users cannot authenticate when the token is lost, misplaced, or unavailable

Engineering Contradiction:
Improveability to authenticateVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces trusted entities as intermediaries between the user and the authentication system. When a user cannot present their authentication token, trusted entities can verify the user's identity through alternative means and facilitate credential recovery, thereby maintaining both security and usability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary verification by trusted entities before allowing credential recovery. This preliminary action ensures that the user's identity is confirmed through alternative channels before restoring access, preventing unauthorized recovery while enabling legitimate users to regain access.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If the system allows credential recovery without trusted entity verification, then user access is restored quickly, but security is compromised

Engineering Contradiction:
Improvecredential recovery speedVSAvoidauthentication security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

Trusted entities serve as mediators that verify user identity during credential recovery. This intermediary verification step balances security requirements with recovery speed, as the trusted entities can quickly confirm identity through pre-established relationships without requiring complex verification procedures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical requirement of physical token possession with a trust-based verification mechanism. Instead of requiring the physical authentication token, the system substitutes a social/organizational trust relationship where trusted entities can verify identity through non-physical means, enabling faster recovery while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If the system requires multiple trusted entities for verification, then security is enhanced, but the complexity of the recovery process increases

Engineering Contradiction:
Improvecredential recovery securityVSAvoidrecovery process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification process is segmented into independent trusted entity validations. Each trusted entity performs a discrete verification task, and their individual confirmations are aggregated to achieve the overall verification goal. This segmentation allows the system to maintain high security through multiple verifications while keeping each individual step simple and manageable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Trusted entities perform self-service verification of the user's identity using their own judgment and existing relationships. Rather than requiring a centralized complex verification system, each trusted entity independently validates the user, simplifying the overall process while maintaining security through distributed verification.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9256725B2Credential recovery with the assistance of trusted entities
Publication Date: 2016.02.09 EMC IP HLDG CO LLC
  • US9256725B2 patent drawing
  • US9256725B2 patent drawing
  • US9256725B2 patent drawing

AI summary

There is disclosed a method for use in credential recovery. In one exemplary embodiment, the method comprises determining a policy that requires at least one trusted entity to verify the identity of a first entity in order to facilitate credential recovery. The method also comprises receiving at least one communication that confirms verification of the identity of the first entity by at least one trusted entity. The method further comprises permitting credential recovery based on the received verification.