Strong Proof Authentication for Account Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
User accounts are vulnerable to attacks due to weak authentication methods like passwords, which can be compromised, allowing malicious users to change security settings and lock out legitimate users.
Innovation Solution
Implementing a system that uses multiple strong proofs associated with a user account, requiring confirmation via these proofs to change security settings, ensuring that changes are only permitted if confirmed by the account holder through stronger verification methods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple strong proofs are required for confirmation, then account security is improved, but the complexity of the authentication system increases
Solution Approach 1:
The authentication system is segmented into multiple independent proof methods (password, email confirmation, SMS code, security questions). Each proof method operates as a separate module that can be individually evaluated, allowing the system to maintain high security through multiple layers while keeping each individual component relatively simple and manageable.
2Reliability
If strong proofs with higher strength than the proof being changed are required, then the security setting change is protected, but the difficulty of detecting and measuring proof strength increases
Solution Approach 1:
The system performs preliminary classification and strength assignment of different proof methods during system setup and configuration. Each proof method (email, SMS, security questions) is pre-evaluated and assigned a strength level. When a security setting change is requested, the system automatically compares the strength of available proofs against the required threshold, eliminating the need for complex real-time analysis of proof strength.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
One or more strong proofs are maintained as associated with an account of a user. In response to a request to change a security setting of the account, an attempt is made to confirm the request by using one of the one or more strong proofs to notify the user. The change is permitted if the request is confirmed via one or more of the strong proofs, and otherwise the change to the security setting of the account is kept unchanged.