Shared MFA OTP Distribution Through Trusted Party Groups
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multifactor authentication systems fail to efficiently distribute one-time passcodes (OTPs) to multiple users sharing a single login credential, leading to timing and coordination issues and potential economic losses in business enterprises.
Innovation Solution
A system generates a system phone number associated with a primary user and trusted parties, allowing OTPs to be sent to this number via SMS or MMS, accessible to the primary user and other group members through a software application, with options for forwarding via email or push notifications, and enabling group members to confirm receipt or designate access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single login credential account is shared by multiple users with traditional 2FA/MFA, then account security is maintained, but login accessibility and coordination efficiency deteriorate because only one user can receive the OTP at a time
Solution Approach 1:
The patent segments the OTP distribution by creating separate communication channels for each group member. The system divides the authentication process into individual segments where each user receives OTPs through their own registered phone numbers or email addresses, eliminating the need for one user to forward codes to others and enabling simultaneous independent access.
Solution Approach 2:
The patent introduces an intermediary system (the authentication service platform) that mediates OTP distribution to multiple users. This intermediary receives authentication requests and distributes OTPs to appropriate group members based on predefined associations, eliminating direct user-to-user coordination and enabling seamless multi-user access.
2Reliability
If OTPs are sent to a single device for shared account access, then security is simplified, but reliability deteriorates because the account becomes inaccessible when the primary device is unavailable
Solution Approach 1:
The patent merges multiple authentication methods (SMS to different phone numbers, email to different addresses) into a unified authentication system. The system combines these diverse channels under a single shared account framework, allowing flexible OTP distribution to multiple users while maintaining a consistent user experience and account management interface.
Solution Approach 2:
The patent changes the parameters of the authentication system by allowing dynamic configuration of OTP delivery methods and recipients. The system can switch between different authentication parameters (different phone numbers, email addresses, delivery methods) based on which group member is attempting to access the account, providing reliability without requiring complex manual configuration.
3Productivity
If multiple users can access a shared account simultaneously, then business productivity is improved, but security risk increases due to potential unauthorized access
Solution Approach 1:
The patent implements preliminary action by requiring group members to pre-register their contact information (phone numbers, email addresses) with the authentication system before attempting to access the shared account. This preliminary registration creates an authorized list of users, ensuring that only pre-approved individuals can receive OTPs and access the account, thereby maintaining security while enabling multi-user productivity.
Data Source
AI summary
Systems, methods, and other aspects for distributing multifactor authentication data to trusted parties are disclosed. A system phone number is assigned to a primary user. A group is created, and the primary user and the system phone number are associated with the group. The primary user causes the system to send invitations to the trusted parties to join the group. The invitations provide links, means, and/or instructions to join the group. The system phone number is used to enroll or register in an account that uses a single sign-on credential requiring two-factor authentication. When the primary user or any trusted users attempts to access the account, the two-factor/multifactor authentication information is sent to the system phone number and is accessible to the primary user and other users through the application (for example, via SMS or push notification), allowing the primary user and the other users to access the account.


