Peer-Based Authentication Using Interaction History
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional client-server user authentication systems are insecure if unique keys are compromised and require users to remember multiple usernames and passwords for different websites and applications, limiting user convenience and security.
Innovation Solution
A method and apparatus for confirming a user's identity by determining relationships between user devices based on interaction histories, allowing authentication without transmitting interaction tables, using proximity checks and interaction patterns to verify user credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional client-server authentication using unique keys is used, then authentication can be performed, but security is compromised if the key becomes known to a malicious third party
Solution Approach 1:
The patent segments the authentication process into multiple independent components: the user's interaction history with peer devices, the peer devices' confirmation of the user's presence, and the server's verification logic. Instead of relying on a single secret key, the system divides authentication into distributed verification steps involving multiple parties (user, peer devices, server), where each component contributes a piece of evidence. This segmentation ensures that compromise of one element does not invalidate the entire authentication mechanism.
Solution Approach 2:
The patent introduces peer devices as intermediaries in the authentication process. These peer devices act as mediators that can confirm the user's presence or identity without the server directly verifying the user's credentials. The peer devices transmit authentication information to the server, serving as a trusted intermediary layer that enhances security by distributing the verification function and reducing the server's exposure to direct authentication attacks.
2Reliability
If traditional username and password authentication is used for each website and application, then user identity can be verified, but users must remember multiple credentials reducing convenience
Solution Approach 1:
The patent implements a universal authentication mechanism that works across multiple websites and applications. Instead of requiring separate username-password pairs for each service, the system uses a single user identity that can be verified through peer device relationships. The server can authenticate the user based on their interaction history with peer devices, making the authentication system multi-functional and applicable to various services without requiring users to manage multiple credentials.
Solution Approach 2:
The system enables users to authenticate themselves without manually providing credentials. The peer devices automatically detect the user's presence and transmit authentication information to the server. The user's interaction history with peer devices serves as self-verified evidence of identity, eliminating the need for users to remember or manually enter multiple passwords while maintaining reliable identity verification.
Data Source
AI summary
The disclosure is related to confirming an identity of a first user of a first user device. An aspect includes receiving a request to confirm the identity of the first user, determining whether or not there is a relationship between the first user or the first user device and a second user of a second user device or the second user device based on a first list of user interactions associated with the first user device and a second list of user interactions associated with the second user device, and confirming the identity of the first user based on determining that there is a relationship between the first user or the first user device and the second user or the second user device.


