Multifactor Authentication Token Reset via Set-Top Box
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic subscription services face security concerns due to unauthorized access, as users may impersonate registered subscribers to gain services without paying, and there is a need for an improved system to reset authentication tokens securely.
Innovation Solution
A method and system for authenticating users by prompting for a first and second authentication token, generating a temporary token, and associating it with a set-top box device or telephone identifier, allowing secure access to subscription services while enabling users to reset forgotten passwords without customer service intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional single-factor authentication is used, then ease of operation is improved, but security deteriorates
Solution Approach 1:
The authentication process is segmented into multiple independent factors: something the user knows (password/PIN), something the user has (authentication token), and something inherent to the user (biometric data). Each factor operates independently but contributes to the overall authentication decision, resolving the contradiction by making the system both secure (multiple factors) and operable (clear step-by-step process).
Solution Approach 2:
An authentication server acts as an intermediary between the user and the system resources. The server receives authentication requests, verifies multiple factors, and mediates access decisions. This intermediary layer enhances security through multi-factor verification while maintaining ease of operation by handling the complex authentication logic centrally, shielding users from complexity.
2Ease of operation
If authentication tokens are easily reset, then ease of operation is improved, but security deteriorates
Solution Approach 1:
Before allowing token reset, the system preliminarily verifies the user's identity through multiple authentication factors (password, biometric data, or existing token). Only after this preliminary verification succeeds is the token reset permitted. This preliminary action ensures that only authorized users can reset tokens, preventing unauthorized access while maintaining ease of operation for legitimate users.
Solution Approach 2:
The system provides feedback during the token reset process by requiring verification through multiple channels (e.g., sending confirmation codes to registered devices, requiring biometric verification). This feedback mechanism ensures that the reset request is legitimate while guiding the user through the process, resolving the contradiction by making reset both secure (multiple verification steps) and user-friendly (clear feedback and guidance).
Data Source
AI summary
A method of resetting authentication token prompts a user of a computing device to transmit a first authentication token associated with an Internet account. The method also prompts the user to transmit a second token associated with the Internet account. The method receives the second authentication token via the computing device and transmitting a temporary authentication token to a set-top box device of the user.


