Distributed Ledger Authentication Route Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional OTP systems fail to authenticate online transactions when SMS messages cannot be delivered due to network outages, poor signal reception, or technological failures, leading to incomplete communication.
Innovation Solution
The implementation of distributed ledger technology to dynamically generate and transfer authentication credentials via alternate communication routes based on network states and user consent, ensuring secure authentication even in cases of primary communication route failures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional OTP systems use SMS messages for authentication, then authentication can be performed through a simple primary communication route, but authentication fails when network outages or poor signal reception occur
Solution Approach 1:
The system dynamically selects communication routes based on real-time network conditions. When the primary SMS route fails, the system automatically transitions to alternative routes such as email, voice calls, or messaging apps, making the authentication system adaptable to changing network states rather than relying on a static single route
Solution Approach 2:
The system pre-establishes multiple alternative communication routes and obtains user consent for their use before authentication failures occur. This preliminary preparation ensures that when network outages happen, the system can immediately switch to pre-approved alternative routes without delay or additional user interaction
2Reliability
If the system implements alternate communication routes to ensure authentication success, then authentication reliability improves, but system complexity increases
Solution Approach 1:
The system introduces a communication route management module that acts as an intermediary between the authentication system and multiple communication channels. This intermediary handles the complexity of route selection, switching, and management centrally, simplifying the overall system architecture while maintaining multiple communication options
Solution Approach 2:
The system implements a universal communication interface that can handle multiple types of communication routes (SMS, email, voice, messaging apps) through a single unified framework. This multi-functional approach allows the system to manage diverse communication channels without requiring separate complex systems for each route
3Reliability
If the system verifies user consent through a scrubbing process before using alternate routes, then security is improved, but authentication time increases
Solution Approach 1:
The system obtains and verifies user consent for alternative communication routes in advance, during account setup or initial configuration. This preliminary consent verification eliminates the need for time-consuming security checks during actual authentication, as the scrubbing process has already confirmed user authorization beforehand
Solution Approach 2:
The system dynamically adjusts the level of consent verification based on the authentication context and user profile. For pre-verified users with established trust levels, the system can streamline the consent check, while maintaining rigorous verification for new or high-risk scenarios, thus balancing security with authentication speed
Data Source
AI summary
Techniques are provided for generating secure, alternate communication routes. In one embodiment, the techniques involve receiving user consent and delivery data, wherein the delivery data includes information for contacting a device associated with a user, receiving an authentication failure indicator corresponding to a primary communication route to reach the user to authenticate an online transaction, initiating a scrubbing process to verify that the user consent indicates permission from a user to transfer an authentication credential via an alternate communication route, identifying a network state, generating the alternate communication route to the user based on the network state, the scrubbing process, and the delivery data, and transferring the authentication credential via the alternate communication route.


