Multi-party Authentication via Management Agent for Offline Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems lack a mechanism for users to access secured files when they forget their passwords, especially in offline scenarios, and fail to provide adequate security for highly sensitive documents, as they do not allow multi-party authorization.
Innovation Solution
Implementing multi-party authentication and authorization processes mediated by a management server or performed peer-to-peer, where users can request authorization from other users or require their presence to access sensitive data, ensuring secure access even without network connectivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If files are stored on individual client devices with standard authentication, then users can access files conveniently, but data security is compromised when users forget passwords or devices are lost
Solution Approach 1:
The patent segments authentication into multiple independent parties (primary authentication and secondary authentication). Instead of relying on a single authentication mechanism, the system divides access control into separate stages: initial authentication to access the management agent, and secondary authentication (biometric or hardware token) to actually access the encrypted file data. This segmentation ensures that even if one authentication layer is compromised, data remains protected.
Solution Approach 2:
The patent introduces a management agent as an intermediary component that sits between the user and the encrypted file data. The management agent handles authentication requests, coordinates with authentication servers, and manages the decryption process. This intermediary layer provides a secure bridge that maintains data protection while enabling legitimate access, resolving the contradiction between convenience and security.
2Reliability
If multi-party authentication is implemented, then data security is enhanced, but system complexity increases
Solution Approach 1:
The management agent is designed as a universal component that handles multiple authentication methods (password-based authentication, biometric authentication, hardware token authentication) through a single interface. This multi-functionality allows the system to support various authentication mechanisms without proportionally increasing complexity, as the management agent provides a unified framework for all authentication types.
Solution Approach 2:
The system implements self-service capabilities where the management agent automatically coordinates authentication processes, manages encryption keys, and handles session management without requiring manual intervention for each authentication step. The agent autonomously communicates with authentication servers, validates credentials, and manages the decryption process, reducing the operational complexity despite the multi-party authentication architecture.
3Adaptability or versatility
If offline authentication is enabled, then access is maintained without network connectivity, but password recovery becomes impossible
Solution Approach 1:
The patent implements preliminary action by requiring secondary authentication (biometric data or hardware token) to be verified before encrypted file data is decrypted and made accessible. This pre-verification step ensures that even in offline mode, the data remains protected by a second authentication layer that cannot be bypassed. The secondary authentication credentials are stored securely in the device, enabling offline verification without requiring network connectivity to authentication servers.
Data Source
AI summary
Disclosed are various examples for multi-party authentication and authentication. In one example, a user can gain access to secured data stored by a managed device based on the presence of the minimum quantity of other users within a threshold proximity of the user who desires access.


