Reverse Entity Authentication via Central Server Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods primarily focus on entities verifying users, making it difficult for users to accurately identify and authenticate entities, especially in the face of increasing malicious activities that can spoof trusted sources, such as caller IDs and communication sender identities.
Innovation Solution
A system comprising a central server, entity hub, and user device that enables users to authenticate entities through an authentication engine, allowing users to request and verify authentication responses from entities, which includes proactive authentication and the sharing of authentication details such as employee IDs, to ensure the authenticity of the communicating party.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current authentication methods (usernames, passwords, biometrics) are used, then entities can authenticate users, but users cannot authenticate entities
Solution Approach 1:
The patent inverts the traditional authentication paradigm by enabling users to authenticate entities rather than entities authenticating users. The system provides users with authentication tools (applying authentication data to a second surface) that allow them to verify entity identity, reversing the conventional direction of authentication and solving the fundamental asymmetry in current systems.
Solution Approach 2:
The patent introduces an authentication system as an intermediary between users and entities. This system includes authentication data, application surfaces, and verification mechanisms that mediate the interaction, allowing users to confidently identify entities without directly exposing sensitive authentication credentials.
2Reliability
If users only discuss sensitive information when they initiate the call, then some security is improved, but it takes extra time and effort and users may skip these steps
Solution Approach 1:
The patent enables preliminary authentication actions where users can verify entity identity before engaging in sensitive communications. The authentication system allows users to apply authentication data and verify entity credentials in advance, ensuring security measures are in place before time-sensitive discussions occur, rather than requiring time-consuming verification during the interaction.
Solution Approach 2:
The system empowers users to perform self-service authentication verification. Users independently apply authentication data to verify entity identity without requiring the entity to take additional time-consuming steps or without needing to skip security measures, making the authentication process both secure and efficient.
3Ease of operation
If malicious actors spoof caller ID, then it appears to be a trusted entity, but the actual authenticity cannot be verified
Solution Approach 1:
The patent employs visual indicators (analogous to color changes) through authentication surfaces and data applications that clearly distinguish authenticated entities from impostors. When authentication data is successfully applied and verified, the system provides visual confirmation to the user, making it immediately apparent whether the entity is genuine or spoofed, thereby solving the problem of distinguishing appearance from reality.
Data Source
AI summary
Apparatus and methods for reverse identification and authentication are provided. The apparatus and methods may include a server receiving a request from a user device to authenticate an entity, forming a communication channel between the entity and the user device, requesting the entity provide authentication credentials, and authenticating the entity. When the entity is authenticated, the server may notify the user through the authentication channel, a mobile device application, or another method. An entity may proactively authenticate itself to a user through the central server, in anticipation of a communication between the entity and user.


