Multi-User Authentication System for Privileged Resource Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods, including multi-factor authentication, are inadequate for securing privileged resources that require simultaneous authentication of multiple users to prevent unauthorized access and ensure legitimate transactions in electronic commerce.

Innovation Solution

A system and method for multi-user authentication that verifies simultaneous login of multiple users within a defined duration, using pre-defined criteria to authorize access requests, ensuring that only authorized users can perform privileged actions on shared resources by requiring multiple users to be online and authenticated simultaneously.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-factor authentication is used for single user verification, then security against unauthorized access is improved, but authentication complexity and user burden increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into distinct phases: initial user login, separate access request submission, and conditional authorization based on meeting pre-defined criteria. This segmentation allows the system to maintain high security requirements while organizing the complexity into manageable, sequential steps that users can follow.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by establishing pre-defined criteria before the actual access decision is made. Users must meet these predetermined requirements (such as providing specific authentication factors or satisfying policy conditions) before their access request can be authorized, allowing the system to prepare security checks in advance rather than ad-hoc.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multi-user simultaneous authentication is required for privileged resources, then security against fraud and identity theft is improved, but authentication process complexity and time required increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system establishes pre-defined criteria in advance that specify what conditions must be met for multi-user authentication. This allows the system to prepare authorization rules, required user combinations, and security policies beforehand, so that when actual access requests occur, the verification process follows predetermined pathways rather than requiring complex real-time decision-making.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic criteria evaluation where the system can adaptively determine whether access requests meet pre-defined criteria based on the specific context, user roles, and security requirements. This dynamic approach allows the system to flexibly adjust authentication requirements without manual reconfiguration, optimizing the balance between security and processing time.

Inventive Principle:
Principle #15Dynamics

3Reliability

If multiple users must be authenticated simultaneously for access, then protection against unauthorized transactions is improved, but system complexity and operational difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidoperational ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the complex multi-user authentication process into distinct, manageable components: user login phase, access request phase, criteria evaluation phase, and authorization phase. Each segment handles a specific aspect of the authentication process, making the overall system easier to operate and understand while maintaining high security through the cumulative effect of all segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements self-service mechanisms by automatically evaluating whether access requests meet pre-defined criteria without requiring manual intervention. The system autonomously manages the multi-user authentication process, comparing user credentials and access requests against predetermined security policies, thereby reducing operational complexity while maintaining rigorous security standards.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9906520B2Multi-user authentication
Publication Date: 2018.02.27 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9906520B2 patent drawing
  • US9906520B2 patent drawing
  • US9906520B2 patent drawing

AI summary

In an approach to multi-user authentication, one or more computer processors receive a first user login. The one or more computer processors determine whether at least one additional user login is received. The one or more computer processors receive an access request from the first user. The one or more computer processors receive an access request from the at least one additional user. In response to receiving the access request from the first user and the access request from the at least one additional user, the one or more computer processors determine whether the access request from the first user and the access request from the at least one additional user meet pre-defined criteria. In response to determining the access requests meet pre-defined criteria, the one or more computer processors authorize the access request of the first user and the access request of the at least one additional user.