Crowd-Based Authentication via Trusted Endorsement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user authentication methods for secure resources face challenges in balancing security and convenience, particularly in scenarios where unregistered users need access, leading to lengthy verification processes and potential user dissatisfaction.
Innovation Solution
An electronic crowd-based authentication system that allows trusted users to endorse unregistered individuals by selecting authentication criteria through a key ring application, pairing it with their own authentication data, and transmitting this data for verification by a security server, thereby granting access to secured resources without requiring full n-factor authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If full n-factor authentication process is applied to unregistered users, then security verification is improved, but user convenience and processing speed deteriorate
Solution Approach 1:
The patent introduces a trusted user as an intermediary who vouches for the unregistered user's identity. Instead of requiring the unregistered user to undergo complete n-factor authentication, the trusted user's endorsement serves as a mediator that validates the unregistered user's credentials, thereby maintaining security while simplifying the authentication process for the unregistered user.
Solution Approach 2:
The trusted user performs preliminary authentication and verification actions before the unregistered user needs to access the resource. By pre-establishing trust through the trusted user's endorsement, the system eliminates the need for the unregistered user to undergo time-consuming authentication steps at the point of access, improving both security and convenience.
2Reliability
If full n-factor authentication process is applied to unregistered users, then security verification is improved, but processing time and queue length deteriorate
Solution Approach 1:
The trusted user performs verification actions in advance by endorsing the unregistered user before they reach the security checkpoint. This preliminary endorsement process transfers the time-consuming verification steps to before the critical access point, reducing waiting time and queue length while maintaining security standards.
Solution Approach 2:
The trusted user acts as a mediator who accelerates the verification process by providing pre-validated endorsement. This intermediary mechanism bypasses the need for the unregistered user to undergo complete authentication procedures at the security gate, significantly reducing processing time while maintaining security through the trusted user's verification.
3Speed
If pre-registration is implemented for frequent users, then authentication speed is improved, but user willingness to register deteriorates
Solution Approach 1:
Instead of requiring users to proactively register with the system (traditional approach), the patent inverts the process by allowing trusted users to endorse unregistered users on-demand. This reversal eliminates the registration barrier while still enabling fast authentication for those who receive endorsements, making the system more appealing to transient users.
Solution Approach 2:
The system enables trusted users to self-initiate the authentication process for their associates without requiring those associates to go through formal registration procedures. This self-service endorsement mechanism allows rapid authentication for trusted individuals while maintaining the option for formal registration for repeat users.
Data Source
AI summary
Methods and systems for electronic crowd-based authentication. An example embodiment includes operations or steps for selecting authentication criteria with corresponding validity criteria through a key ring application, pairing the key ring application with authentication data, and transmitting the authentication data for verification by a security server, thereby allowing a trusted user to endorse an unregistered user to provide the unregistered user with access to a secured resource by the selecting of the authentication criteria, the pairing of the key ring application, and the transmitting of the authentication data for verification by the security server.


