Tiered Authentication System for Balancing Security and Convenience

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network-enabled computing systems face inefficiencies in user authentication, particularly when multiple users share a device, as they require frequent logging in, logging out, and re-authentication, which is time-consuming and frustrating.

Innovation Solution

Implementing a tiered authentication system that determines the level of authentication required based on the service requested, using high quality authentication (e.g., biometrics) for critical actions and low quality authentication (e.g., image recognition, accelerometer data) for less critical actions, allowing for automatic and periodic authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication systems are used for all services, then security is maintained, but user convenience and authentication frequency are significantly reduced

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by differentiating authentication requirements across different services and contexts. High-quality authentication (biometrics, passwords) is applied to critical services like financial transactions and account management, while low-quality authentication (device recognition, contextual cues) is applied to less sensitive services like media playback or browsing. This resolves the contradiction by optimizing security where needed while maximizing convenience where appropriate.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts authentication requirements based on the service being accessed, user behavior patterns, and security risk assessment. The authentication level is not static but adapts in real-time, switching between high-quality and low-quality authentication methods based on contextual factors such as location, time, device state, and service sensitivity.

Inventive Principle:
Principle #15Dynamics

2Reliability

If high quality authentication is required for all services, then security is maximized, but authentication time and system complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies partial authentication action by using low-quality authentication methods for services that do not require full security verification. Instead of always performing complete high-quality authentication, the system uses contextual information and device state to determine when simplified authentication is sufficient, thereby reducing authentication time while maintaining appropriate security levels.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If high quality authentication is required for all services, then security is maximized, but device complexity and implementation difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into multiple quality levels and independent modules. High-quality authentication components (biometric sensors, secure key storage) and low-quality authentication components (device identifiers, contextual sensors) are separated and can be selectively activated based on service requirements. This modular segmentation reduces overall system complexity while maintaining security where needed.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10154410B2Systems and methods for authentication using low quality and high quality authentication information
Publication Date: 2018.12.11 PAYPAL INC
  • US10154410B2 patent drawing
  • US10154410B2 patent drawing
  • US10154410B2 patent drawing

AI summary

Systems, methods, and devices for authenticating a user are provided. A device includes one or more processors configured to determine if a requested service requires high quality authentication, generate a request for high quality authentication if the requested service requires high quality authentication, and generate a request for low quality authentication if the requested service requires low quality authentication. The device also include a network interface component coupled to a network, the network interface component configured to: receive the request for the service requiring authentication, and a memory, the memory storing high quality authentication information and low quality authentication information for authenticating the user.