Trusted Party Authentication for Secure Account Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing online service platforms face challenges in securely sharing account information and details between users, particularly when one user forgets login credentials or needs access from a different device, leading to system inaccessibility and decreased user satisfaction.

Innovation Solution

A computer-implemented method and system that allows a server to host online services with multiple user accounts configured for concurrent access sessions, enabling a first user to authenticate a second user by transmitting a login request notification with a GUI element, allowing secure sharing of account details between trusted parties.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used where each user must independently log in with credentials, then security is maintained, but system inaccessibility occurs when users forget credentials or need access from different devices

Engineering Contradiction:
Improvesystem accessibilityVSAvoidlogin complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a trusted party as an intermediary who receives authentication requests and forwards them to the target account. This mediator enables access when the original user cannot authenticate directly, resolving the contradiction between maintaining security and ensuring system accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication by obtaining approval from the account owner before allowing access from new devices or by other users. This advance authorization mechanism prevents authentication issues later while maintaining security controls.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If account credentials are shared between users, then ease of access is improved, but security and privacy are compromised

Engineering Contradiction:
Improveaccount sharing convenienceVSAvoidsecurity and privacy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements feedback mechanisms where account owners receive notifications about authentication requests and can approve or deny them. This controlled feedback loop enables sharing while maintaining security, as owners remain informed and can revoke access when needed.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The authentication system transitions from static credential sharing to dynamic, context-aware authentication where access rights can change based on device, location, and user approval. This dynamic approach enables flexible sharing while maintaining security controls.

Inventive Principle:
Principle #15Dynamics

3Productivity

If multiple concurrent access sessions are allowed, then service utilization is improved, but authentication management complexity increases

Engineering Contradiction:
Improveservice utilizationVSAvoidauthentication management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments authentication management by creating separate authentication flows for different scenarios: standard login, trusted party authentication, and device-specific authentication. This segmentation simplifies management complexity while enabling multiple concurrent sessions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication system is designed with multi-functionality to handle various authentication scenarios through a unified framework. The same trusted party mechanism works across different devices and user types, reducing overall system complexity despite supporting multiple concurrent accesses.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240073215A1Computer-based systems involving sharing session authentication and/or account details with a trusted party and methods of use thereof
Publication Date: 2024.02.29 CAPITAL ONE SERVICES LLC
  • US20240073215A1 patent drawing
  • US20240073215A1 patent drawing
  • US20240073215A1 patent drawing

AI summary

Systems and methods associated with sharing encrypted account details with a trusted party are disclosed. In one embodiment, an exemplary method may comprise hosting an online service accessed by a plurality of user accounts each configured for concurrent access sessions, establishing a first authenticated access session for a first user account between the online service and a first device associated with a first user, receiving a login request associated with the first user account to establish a second authenticated access session between the online service and a second device associated with a second user, transmitting, to the first device, a notification of the login request including a GUI element and a request to authenticate the login request, and establishing the second authenticated access session between the online service and the second device of the second user based on authentication of the second user via the GUI element.