Peer-Assisted Access Recovery for Lost Authentication Factors
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital identity and access management systems face inefficiencies and delays when users lose or forget authentication factors, particularly possession factors, leading to costly and time-consuming authority-based or self-service recovery procedures that do not provide timely solutions.
Innovation Solution
Implementing peer trust-based recovery procedures that leverage pre-registered authentication helpers to validate the user's identity and provide an additional authentication factor, allowing users to recover access efficiently and securely without relying solely on traditional authority-based or self-service methods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authority-based recovery procedures are used, then security is maintained, but cost and time consumption increase significantly
Solution Approach 1:
The patent enables users to perform self-service recovery by having them select and communicate with trusted helpers from a pre-configured list. The system automatically manages the recovery process, including validating helper identities, coordinating authentication factors, and restoring access without requiring manual intervention from IT administrators or security authorities.
Solution Approach 2:
The patent introduces trusted helpers as intermediary entities between the user and the authentication system. These helpers act as mediators who can verify user identity and provide alternative authentication factors when primary factors are lost, thereby enabling recovery without direct authority intervention.
2Productivity
If self-service recovery procedures are used, then cost is reduced, but timeliness deteriorates for possession factor loss
Solution Approach 1:
The patent requires users to pre-configure trusted helpers and establish their identities with the authentication system before actual recovery events occur. This preliminary setup includes storing helper contact information, establishing communication channels, and pre-validating helper credentials, so that when recovery is needed, the entire process can execute immediately without setup delays.
Solution Approach 2:
The system enables users to autonomously initiate recovery by selecting from pre-approved helpers and automatically triggers the recovery workflow. The system handles all coordination, validation, and authentication factor substitution automatically, eliminating the need for user interaction with IT support and significantly reducing recovery time compared to traditional self-service email-based methods.
3Ease of operation
If traditional authentication factors are used, then ease of use is maintained, but vulnerability to loss increases
Solution Approach 1:
The patent implements different authentication strategies for different contexts and user needs. For routine access, traditional convenient factors (passwords, mobile devices) are used. When loss is detected, the system automatically switches to alternative authentication factors provided by trusted helpers. This localized adaptation of authentication methods ensures both ease of use for normal operations and enhanced security when factors are compromised.
Solution Approach 2:
The system dynamically changes authentication parameters based on the situation. When a user reports loss of a factor, the system modifies the authentication requirements by accepting alternative factors from trusted helpers instead of the lost factor. This parameter change allows the system to maintain security while adapting to the changed circumstances of factor availability.
Data Source
AI summary
The technology disclosed teaches systems, methods, and media for enabling a user to recover from a loss of one or more authentication factors that are required in order to access a service. A pre-registered helper user is able to participate in the authentication journey on behalf of the user and provide an identity validation of the user in order to successfully authenticate the user in order for an authentication journey server to grant the user access to the service. The technology disclosed further teaches systems, methods, and media obtaining secondary approval for a request to initiate a restricted action during a first active session between a user and a service. A pre-registered supervisor user is able to participate in the authentication journey on behalf of the user and provide a secondary approval for the request in order for an authentication journey server to grant the user access to the service.


