Dynamic Authentication System Using Two-Pass Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current online authentication systems are vulnerable to fraud and security breaches due to the reliance on easily guessable passwords and lack of robust authentication mechanisms, leading to billions of dollars in lost revenue and compromised user data, as businesses hesitate to adopt stronger authentication methods due to high upfront costs and complexity.
Innovation Solution
A dynamic authentication system that provides centralized, non-federated, proxied authentication, utilizing a two-pass process to dynamically select authentication methods based on user behavior, time, and resource sensitivity, allowing users to manage authentication tokens across multiple accounts with enhanced security features like hardware tokens and real-time alerts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If websites implement stronger authentication mechanisms, then security is improved, but device complexity and upfront costs increase
Solution Approach 1:
The patent introduces a third-party authentication service as an intermediary between users and websites. This service handles the complex authentication processes centrally, allowing individual websites to adopt strong authentication without bearing the full complexity burden. The intermediary manages token generation, verification, and coordination across multiple sites, reducing the authentication system complexity at each individual website while maintaining high security standards.
Solution Approach 2:
The authentication service is designed to be universal and multi-functional, serving multiple websites and users through a single platform. It provides various authentication methods (passwords, hardware tokens, software tokens) and can adapt to different security requirements. This universality allows the system to achieve high reliability across diverse applications without requiring each website to develop and maintain separate complex authentication systems.
2Reliability
If users manage multiple passwords for different sites, then authentication security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent merges the authentication management function into a single centralized service that users interact with once. Instead of managing separate passwords for each website, users authenticate through a unified system that handles multiple sites. The service combines password management, token generation, and verification into one interface, significantly improving ease of operation while maintaining security through the use of multiple authentication factors when needed.
Solution Approach 2:
The authentication service provides self-service capabilities where users can manage their own authentication credentials, view security status, and control their authentication methods without requiring assistance from individual websites. The system automatically generates tokens, verifies credentials, and coordinates authentication across multiple sites, reducing the operational burden on users while maintaining strong security practices.
3Ease of operation
If users use easy-to-remember passwords, then ease of operation is improved, but reliability deteriorates
Solution Approach 1:
The patent changes the authentication parameters from simple passwords to multi-factor authentication including hardware tokens and software tokens. Users can still remember a single password easily, but the system enhances security by adding additional authentication factors that do not rely on memorability. The service dynamically adjusts authentication parameters based on risk assessment, using stronger methods when needed while maintaining ease of operation for low-risk scenarios.
Solution Approach 2:
The centralized authentication service acts as an intermediary that manages the transition from simple passwords to more secure authentication methods. It handles the complexity of multi-factor authentication while presenting a simple interface to users. The service can issue hardware tokens or software tokens that work with easy-to-remember passwords, combining the ease of operation with improved reliability through the intermediary's coordination of multiple authentication factors.
4Reliability
If websites implement centralized authentication, then reliability is improved, but device complexity increases
Solution Approach 1:
The patent introduces a centralized authentication service as an intermediary that assumes the complexity burden. Individual websites do not need to implement their own complex authentication infrastructure; instead, they integrate with the centralized service through standardized interfaces. The intermediary manages user credentials, generates authentication tokens, and coordinates verification across all participating websites, thereby improving reliability while preventing the proliferation of complex authentication systems at each individual site.
Solution Approach 2:
The authentication system is segmented into distinct functional components: user registration, credential storage, token generation, verification, and session management. The centralized service handles the complex segments (credential storage, token generation), while websites only need to implement simple integration segments (authentication requests and responses). This segmentation allows the system to achieve high reliability through centralized management without imposing full complexity on individual websites.
Data Source
AI summary
A dynamic authentication system that makes authentication stronger, while reducing the cost to business and the burden to users. The system includes a service that provides centralized, non-federated, proxied authentication. The system uses a two-pass authentication process that first receives a supposed identity of the user and then determines one or more authentication criteria for proving that supposed identity. When the user attempts to use an online service that relies on the dynamic authentication system for authentication, the service requests the user's identity. The system dynamically determines authentication criteria for the user to prove the provided identity belongs to the user. In the second pass, the service receives a response from the user containing additional authentication information, and forwards the received response to the system for verification. If verification succeeds, the service allows the user to access the requested resources.


