Touchless Command Authentication for Protected Actions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital assistants on information handling devices face security challenges in differentiating between sensitive and non-sensitive touchless commands, as conventional authentication methods like passwords and voice recognition are not reliable or secure, especially when users provide commands without physical input, allowing unauthorized access to perform sensitive actions.
Innovation Solution
A method that receives touchless commands and determines whether they correspond to protected or unprotected actions, requesting user authentication only for protected actions, which can be performed locally or through other devices, using techniques like facial recognition or fingerprint identification, to ensure secure execution of sensitive commands.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional authentication methods like passwords and voice recognition are used for touchless commands, then user convenience is improved, but security reliability deteriorates due to unauthorized access risks
Solution Approach 1:
The patent segments authentication requirements by categorizing actions into protected and unprotected types. Touchless commands for unprotected actions are executed without authentication to maintain convenience, while protected actions require authentication through multiple factors (biometric, possession, knowledge) to ensure security. This segmentation resolves the contradiction by applying different authentication strictness levels to different action types.
Solution Approach 2:
The system performs preliminary classification of actions as protected or unprotected before execution. This preliminary action allows the system to prepare appropriate authentication requirements in advance, enabling touchless execution for safe actions while pre-configuring security checks for sensitive actions, thus balancing convenience and security.
2Reliability
If authentication is required for all touchless commands, then security reliability is improved, but ease of operation deteriorates due to additional authentication steps
Solution Approach 1:
The patent applies local quality by making authentication requirements specific to each action type rather than uniform across all commands. Protected actions (e.g., financial transactions, data deletion) require authentication, while unprotected actions (e.g., setting reminders, playing music) execute without authentication. This localized approach ensures security where needed while maintaining operational ease where risks are minimal.
Solution Approach 2:
The system applies partial authentication action by requiring authentication only for protected actions rather than all touchless commands. This partial application of authentication maintains security for critical operations while avoiding unnecessary authentication steps for routine tasks, thus preserving ease of operation.
3Reliability
If multiple authentication factors are required for protected actions, then security reliability is improved, but device complexity increases
Solution Approach 1:
The patent implements multi-functionality by designing an authentication system that can handle multiple authentication factors (biometric, possession, knowledge) within a single unified framework. The system universally supports various authentication methods and can adaptively select appropriate combinations based on the protected action's security requirements, reducing the need for separate authentication systems for each factor.
Solution Approach 2:
The system introduces an intermediary authentication manager that coordinates between different authentication factors and the protected actions. This intermediary component simplifies the overall system architecture by centralizing authentication logic, managing credential verification, and orchestrating multi-factor authentication sequences, thereby reducing device complexity despite supporting multiple authentication methods.
Data Source
AI summary
One embodiment provides a method, including: receiving, at an information handling device, a touchless command to perform an action; determining, using a processor, whether the action is one of: a protected action and an unprotected action; and requesting, responsive to determining that the action is associated with a protected action, user authentication input prior to performing the action. Other aspects are described and claimed.


