Multi-party Authentication via Management Agent for Offline Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems lack a mechanism for users to access secured files when they forget their passwords, especially in offline scenarios, and fail to provide adequate security for highly sensitive documents, as they do not allow multi-party authorization.

Innovation Solution

Implementing multi-party authentication and authorization processes mediated by a management server or performed peer-to-peer, where users can request authorization from other users or require their presence to access sensitive data, ensuring secure access even without network connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If files are stored on individual client devices with standard authentication, then users can access files conveniently, but data security is compromised when users forget passwords or devices are lost

Engineering Contradiction:
Improvefile access convenienceVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments authentication into multiple independent parties (primary authentication and secondary authentication). Instead of relying on a single authentication mechanism, the system divides access control into separate stages: initial authentication to access the management agent, and secondary authentication (biometric or hardware token) to actually access the encrypted file data. This segmentation ensures that even if one authentication layer is compromised, data remains protected.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a management agent as an intermediary component that sits between the user and the encrypted file data. The management agent handles authentication requests, coordinates with authentication servers, and manages the decryption process. This intermediary layer provides a secure bridge that maintains data protection while enabling legitimate access, resolving the contradiction between convenience and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multi-party authentication is implemented, then data security is enhanced, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The management agent is designed as a universal component that handles multiple authentication methods (password-based authentication, biometric authentication, hardware token authentication) through a single interface. This multi-functionality allows the system to support various authentication mechanisms without proportionally increasing complexity, as the management agent provides a unified framework for all authentication types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements self-service capabilities where the management agent automatically coordinates authentication processes, manages encryption keys, and handles session management without requiring manual intervention for each authentication step. The agent autonomously communicates with authentication servers, validates credentials, and manages the decryption process, reducing the operational complexity despite the multi-party authentication architecture.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If offline authentication is enabled, then access is maintained without network connectivity, but password recovery becomes impossible

Engineering Contradiction:
Improveoffline access capabilityVSAvoidpassword recovery
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by requiring secondary authentication (biometric data or hardware token) to be verified before encrypted file data is decrypted and made accessible. This pre-verification step ensures that even in offline mode, the data remains protected by a second authentication layer that cannot be bypassed. The secondary authentication credentials are stored securely in the device, enabling offline verification without requiring network connectivity to authentication servers.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11361101B2Multi-party authentication and authorization
Publication Date: 2022.06.14 OMNISSA LLC
  • US11361101B2 patent drawing
  • US11361101B2 patent drawing
  • US11361101B2 patent drawing

AI summary

Disclosed are various examples for multi-party authentication and authentication. In one example, a user can gain access to secured data stored by a managed device based on the presence of the minimum quantity of other users within a threshold proximity of the user who desires access.