Trusted Party Authentication for Secure Account Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing online service platforms face challenges in securely sharing account information and details between users, particularly when one user forgets login credentials or needs access from a different device, leading to system inaccessibility and decreased user satisfaction.
Innovation Solution
A computer-implemented method and system that allows a server to host online services with multiple user accounts configured for concurrent access sessions, enabling a first user to authenticate a second user by transmitting a login request notification with a GUI element, allowing secure sharing of account details between trusted parties.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used where each user must independently log in with credentials, then security is maintained, but system inaccessibility occurs when users forget credentials or need access from different devices
Solution Approach 1:
The patent introduces a trusted party as an intermediary who receives authentication requests and forwards them to the target account. This mediator enables access when the original user cannot authenticate directly, resolving the contradiction between maintaining security and ensuring system accessibility.
Solution Approach 2:
The system performs preliminary authentication by obtaining approval from the account owner before allowing access from new devices or by other users. This advance authorization mechanism prevents authentication issues later while maintaining security controls.
2Ease of operation
If account credentials are shared between users, then ease of access is improved, but security and privacy are compromised
Solution Approach 1:
The system implements feedback mechanisms where account owners receive notifications about authentication requests and can approve or deny them. This controlled feedback loop enables sharing while maintaining security, as owners remain informed and can revoke access when needed.
Solution Approach 2:
The authentication system transitions from static credential sharing to dynamic, context-aware authentication where access rights can change based on device, location, and user approval. This dynamic approach enables flexible sharing while maintaining security controls.
3Productivity
If multiple concurrent access sessions are allowed, then service utilization is improved, but authentication management complexity increases
Solution Approach 1:
The patent segments authentication management by creating separate authentication flows for different scenarios: standard login, trusted party authentication, and device-specific authentication. This segmentation simplifies management complexity while enabling multiple concurrent sessions.
Solution Approach 2:
The authentication system is designed with multi-functionality to handle various authentication scenarios through a unified framework. The same trusted party mechanism works across different devices and user types, reducing overall system complexity despite supporting multiple concurrent accesses.
Data Source
AI summary
Systems and methods associated with sharing encrypted account details with a trusted party are disclosed. In one embodiment, an exemplary method may comprise hosting an online service accessed by a plurality of user accounts each configured for concurrent access sessions, establishing a first authenticated access session for a first user account between the online service and a first device associated with a first user, receiving a login request associated with the first user account to establish a second authenticated access session between the online service and a second device associated with a second user, transmitting, to the first device, a notification of the login request including a GUI element and a request to authenticate the login request, and establishing the second authenticated access session between the online service and the second device of the second user based on authentication of the second user via the GUI element.


