Trust Transfer Between Authentication Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user authentication systems for secure online services require multiple and often cumbersome verification processes, especially when accessing different secure online resources, as each authenticator needs to be independently verified, leading to increased user effort and redundancy.
Innovation Solution
A method and system that allow an authentication device to be associated with a user by transferring trust from another already associated authentication device, enabling the first authenticator to authenticate the user based on identity assurance indicators verified for the second authenticator, thus reducing the need for multiple verification processes and enhancing efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If each authenticator is independently verified, then security reliability is improved, but user effort and authentication complexity increase
Solution Approach 1:
The patent introduces a trust transfer mechanism where an already verified authenticator (second authenticator) acts as an intermediary to vouch for a new authenticator (first authenticator). The authentication server receives an authentication message from the first authenticator, verifies it through the second authenticator that is already associated with the user, and thereby establishes trust without requiring complete independent verification of the first authenticator. This mediator approach maintains security while reducing user effort.
Solution Approach 2:
The system performs preliminary verification by requiring the user to have at least one authenticator (second authenticator) already associated and verified before enabling trust transfer. This preliminary action of establishing an initial trusted authenticator allows subsequent authenticators to be quickly associated through trust transfer, reducing the need for repeated full verification processes.
2Reliability
If multiple authentication methods are combined, then authentication reliability is improved, but device complexity and verification redundancy increase
Solution Approach 1:
The patent implements a universal authentication framework where a single trust transfer mechanism can handle multiple authentication scenarios and methods. The authentication server can process trust transfer requests regardless of the specific authentication method used by the second authenticator, making the system multi-functional and reducing the need for separate verification processes for different authentication types.
Solution Approach 2:
The system merges multiple authentication methods and verification processes into a unified trust transfer mechanism. Instead of maintaining separate verification flows for different authentication methods, the patent combines them under a single framework where the authentication server handles trust transfer uniformly, reducing system complexity while maintaining the benefits of multiple authentication methods.
3Reliability
If independent verification is performed for each authenticator, then security is improved, but authentication time and efficiency decrease
Solution Approach 1:
By using the second authenticator as an intermediary that is already verified, the system avoids time-consuming independent verification of the first authenticator. The trust transfer through the intermediary authenticator establishes security quickly, reducing authentication time while maintaining security standards.
Solution Approach 2:
The preliminary verification of the second authenticator is performed once and stored in the authentication server. When the user needs to use a new first authenticator, the server leverages this pre-established trust relationship through trust transfer, avoiding repeated full verification processes and significantly reducing authentication time for subsequent logins.
Data Source
AI summary
Disclosed herein are methods and systems for transferring trust between authentication devices associated with the same user. The user accessing secure online resource(s) uses a first (authentication) client device which is not yet associated (verified) with the user for accessing the secure online resource(s). In response to receiving an authentication request from the client device, an authentication message is transmitted to the first client device. The authentication message is transferred from the first client device to a second client device already associated (verified) with the user for accessing the secure online resource(s). The second authenticator transmits back the authentication message which may be verified against the authentication message transmitted to the first client device. In case of successful verification, the first authenticator is associated with the user and enabled for authenticating the user when accessing for secure online resource(s) based on identity assurance indicator(s) verified for the second client device.


