Multi-Person Facial Authentication via Intermediary Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication technologies are vulnerable to compromise by bad actors, as they often rely on single-user input such as passwords, which can be stolen or intercepted, leading to unauthorized access to secure information and services.

Innovation Solution

A multi-person authentication system that requires facial recognition verification of at least two authorized individuals before granting access to secure information and services, using a challenge-response message and push notifications to ensure secure and efficient authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If single-user authentication (password, PIN) is used, then authentication process is simple and quick, but security is vulnerable to compromise by bad actors

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is segmented into multiple independent verification steps: (1) initial credential verification, (2) biometric authentication of the user, and (3) biometric authentication of a confirming individual. This segmentation transforms a single vulnerable authentication step into multiple layered security checks, directly addressing the security vulnerability while maintaining manageable system complexity through modular implementation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A confirming individual acts as an intermediary who provides an additional layer of verification. The confirming individual receives a notification, verifies the user's identity through biometric matching, and provides confirmation before access is granted. This intermediary mechanism enhances security without requiring complex cryptographic protocols or hardware security modules.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multi-person authentication with facial recognition is implemented, then unauthorized access is reduced, but authentication time and process complexity increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Biometric templates for both the user and confirming individual are pre-registered and stored in the system before authentication is needed. During the authentication process, the system performs real-time biometric capture and comparison against these pre-existing templates, eliminating the need for manual verification or complex real-time analysis, thus reducing authentication time while maintaining high reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual verification processes (such as visual inspection of identification documents or in-person meeting) with automated biometric recognition technology. The system captures facial images, extracts biometric features, and automatically compares them against stored templates, significantly reducing authentication time and eliminating human error in the verification process.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11792188B2Application for confirming multi-person authentication
Publication Date: 2023.10.17 BANK OF AMERICA CORP
  • US11792188B2 patent drawing
  • US11792188B2 patent drawing
  • US11792188B2 patent drawing

AI summary

A secure server is configured to host one or more secure applications. A first user device includes a camera operable to capture a first image of a first user of the first user device. The first user device receives a notification that indicates confirmation of authentication of a second user of a second user device is needed after the second user requests access to the secure server. Following receipt of the notification, the first user device captures a first image of the first user. The first image includes at least a portion of a face of the first user. Facial recognition is performed, and results of facial recognition are provided to the second user device where it is used for multi-person authentication.