Trusted-User Authentication for Mobile-Device-Free MFA
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-factor authentication (MFA) methods fail to provide efficient and secure alternative authentication when users cannot access their mobile devices due to loss, damage, or power issues, and existing email-based and manual verification methods are insecure or costly.
Innovation Solution
An authentication method and system that utilizes identification information from trusted users to verify a first password, determining authentication assistance qualifications and employing a multi-factor authentication server to confirm the identity of the user, optionally involving additional password verification via email.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If email-based OTP authentication is used as alternative MFA method, then authentication can be provided when mobile device is unavailable, but security is compromised because the same account is shared between information system and email system
Solution Approach 1:
The patent introduces a dedicated alternative authentication mechanism that acts as an intermediary between the user and the system. Instead of reusing the email account (which shares credentials with the information system), a separate authentication channel is established through trusted contacts who receive verification codes via SMS or call. This mediator approach allows authentication to proceed when the user's mobile device is unavailable, while maintaining security by not relying on the potentially compromised email account credentials.
2Adaptability or versatility
If manual authentication by internal specialists is used, then authentication can be performed without user's mobile device, but execution efficiency decreases due to complicated verification process and high development cost
Solution Approach 1:
The patent implements a self-service alternative authentication mechanism where the system automatically manages the verification process without requiring manual intervention from internal specialists. When a user cannot access their mobile device, the system automatically sends verification codes to pre-configured trusted contacts (such as family members or colleagues) via SMS or phone calls. The authentication flow is automated, with the system handling code generation, distribution, and verification, thereby eliminating the need for complicated manual verification processes and reducing execution time significantly.
3Adaptability or versatility
If manual authentication by internal specialists is used, then authentication can be performed without user's mobile device, but development cost increases
Solution Approach 1:
The patent designs a universal alternative authentication mechanism that leverages existing infrastructure (SMS gateway, phone system, database) already present in most organizations. The trusted contact authentication system can serve multiple purposes: it provides alternative MFA when mobile devices are unavailable, enables account recovery, and can verify user identity in various scenarios. By making the authentication system multi-functional and reusing existing resources, the development cost is significantly reduced compared to building dedicated manual verification systems.
Data Source
AI summary
An authentication method executed by the processing device of a computer system is provided. The method includes the following operations. The method includes requesting identification information from a user device, in response to receiving an authentication assistance request from the user device. The method further includes receiving the identification information of a second user from the user device. Based on the identification information of the second user, the method further includes determining whether the second user meets an authentication assistance qualification corresponding to a first user. The method further includes requesting a first password from the user device when the second user meets the authentication assistance qualification. The method further includes receiving the first password from the user device and verifying whether the first password is correct using a multi-factor authentication server.


