Trusted Party Authentication for Secure Account Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing online service platforms face challenges in securely sharing account information between users, particularly when one user forgets login credentials or needs access from a different device, leading to system inaccessibility and security risks.
Innovation Solution
A computer-implemented method that allows a server to host online services with multiple user accounts configured for concurrent access sessions, where a login request notification is sent to a trusted user's device to authenticate a second user's access, enabling secure sharing of account details through a graphical user interface.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used where each user must independently remember login credentials, then security is maintained, but system inaccessibility occurs when users forget credentials or need access from different devices
Solution Approach 1:
The patent introduces a trusted party as an intermediary in the authentication process. When a user needs to access the system, the trusted party receives a challenge, generates a response using their own credentials, and transmits it to the server. This mediator approach allows users to access the system without directly sharing credentials while maintaining security through the trusted party's involvement.
Solution Approach 2:
The system enables self-service authentication where the trusted party autonomously responds to authentication challenges without requiring direct intervention from the user seeking access. The trusted party's device automatically receives challenges, generates appropriate responses using stored credentials, and transmits them back, creating a self-service authentication mechanism that improves accessibility.
2Ease of operation
If account credentials are shared between users to enable access, then ease of operation improves, but security risks increase due to potential credential exposure
Solution Approach 1:
The trusted party acts as a secure intermediary that never exposes actual credentials. Instead of sharing passwords or authentication tokens, the system uses the trusted party's credentials securely stored on their device to generate authentication responses. This intermediary approach enables account sharing functionality while eliminating the security risks associated with credential exposure.
Solution Approach 2:
The system creates cryptographic copies or representations of authentication credentials rather than using the actual credentials themselves. The trusted party's credentials are used to generate authentication responses that are transmitted to the server, effectively creating a secure copy mechanism that enables access without exposing the original credentials.
3Ease of operation
If multiple concurrent authenticated access sessions are allowed, then ease of operation improves for family or team accounts, but device complexity and security management become more challenging
Solution Approach 1:
The trusted party's device serves as a centralized intermediary that manages authentication for multiple concurrent sessions. Instead of each user device needing to independently manage authentication state, the trusted party's device receives and processes authentication challenges, coordinating access across multiple users and devices while simplifying the overall session management architecture.
Data Source
AI summary
Systems and methods associated with sharing encrypted account details with a trusted party are disclosed. In one embodiment, an exemplary method may comprise hosting an online service accessed by a plurality of user accounts each configured for concurrent access sessions, establishing a first authenticated access session for a first user account between the online service and a first device associated with a first user, receiving a login request associated with the first user account to establish a second authenticated access session between the online service and a second device associated with a second user, transmitting, to the first device, a notification of the login request including a GUI element and a request to authenticate the login request, and establishing the second authenticated access session between the online service and the second device of the second user based on authentication of the second user via the GUI element.


