Automated Human-Assisted Authentication via Trusted Associate Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional authentication methods are inadequate for scenarios where users forget or lose credentials, as they require expensive equipment or publicly available information, and are not feasible in all settings, such as home internet connections.
Innovation Solution
An automated human-assisted authentication system that contacts trusted associates via voice or video communication to validate user identity using one-time passwords, which are combined to form an authentication password for authorizing actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods (retina scanner, fingerprint recorder) are used, then authentication reliability is improved, but device cost and complexity increase significantly
Solution Approach 1:
The patent introduces trusted associates as intermediaries between the user and the authentication system. Instead of using complex biometric devices, the system uses human associates who can verify identity through simple questions, thereby reducing device complexity while maintaining authentication reliability
Solution Approach 2:
The patent replaces mechanical/biometric authentication systems (retina scanners, fingerprint recorders) with a communication-based system using voice or video calls to trusted associates, eliminating the need for expensive sensing equipment while achieving reliable authentication
2Reliability
If additional identifying information (mother's maiden name, pet's name) is requested, then authentication reliability is improved, but security vulnerability increases due to publicly available information
Solution Approach 1:
The patent uses trusted associates as intermediaries who ask personalized questions that are not publicly available. This approach maintains authentication reliability while avoiding the security vulnerability of using easily discoverable personal information, as the questions and answers remain private between the user and their trusted associates
Solution Approach 2:
The patent shifts from verifying static personal information (mother's maiden name) to dynamic verification through real-time communication with trusted associates. This dimensional shift from information-based authentication to interaction-based authentication eliminates the vulnerability to publicly available information while maintaining reliability
3Reliability
If expensive sensing equipment is used, then authentication reliability is improved, but accessibility and ease of operation deteriorate in home internet settings
Solution Approach 1:
The patent employs trusted associates as intermediaries who can perform verification using only standard communication devices (phone, video call), making the system accessible in home internet settings without requiring expensive specialized equipment, thereby improving ease of operation while maintaining authentication reliability
Solution Approach 2:
The patent creates a universal authentication method that works across multiple platforms and devices (phone, video call, internet connection) without requiring specialized equipment. This multi-functional approach enables reliable authentication in diverse settings including home internet connections, greatly improving ease of operation
Data Source
AI summary
A server computing system receives a request to authenticate the identity of a user. The user may wish to perform an action that requires the user's identity to first be verified. In response to the request, the server computing system automatically contacts trusted associates that are listed in policy data for the user and determines whether the trusted associates validate the identity of the user. The server computing system provides one-time passwords to the user for the trusted associates that have validated the identity of the user. Subsequently, the user can combine the one-time passwords to form an authentication password, which can be used to determine whether the user is allowed to perform the action.


