Trustee-Based Data Transfer Authorization System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data transfer authorization methods, such as two-factor authentication, can be frustrating and unhelpful for vulnerable individuals like the elderly, as they often require customer involvement, which may not be feasible or reliable, especially when customers are temporarily unable to access their devices or networks.
Innovation Solution
A system and method that allows customers to designate trusted individuals or trustees within a network of trust, enabling third-party authentication for data transfers without requiring customer involvement, thus authorizing data transfers based on trustee confirmation even in the absence of customer authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If two-factor authentication is used for data transfer authorization, then security is improved, but ease of operation deteriorates for vulnerable customers
Solution Approach 1:
The patent introduces a trustee as an intermediary who performs second-factor authentication on behalf of the customer. The trustee receives authentication requests, verifies the customer's identity through alternative means, and submits authentication responses to the authentication system, thereby eliminating the need for the customer to directly interact with the authentication process while maintaining security
2Reliability
If customer involvement is required in authentication processes, then authentication reliability is improved, but productivity deteriorates when customers are temporarily unable to access their devices
Solution Approach 1:
The system performs preliminary verification by checking whether the customer computing device is associated with a trustee in the system of trust before initiating the authentication process. This preliminary action allows the system to proactively route authentication requests to the appropriate trustee, ensuring that authentication can proceed without requiring customer device access while maintaining security standards
3Ease of operation
If third-party authentication is implemented, then ease of operation is improved for vulnerable customers, but device complexity increases
Solution Approach 1:
The trustee computing device is designed with multi-functionality, serving both as a standard computing device for the trustee's personal use and as an authentication intermediary for the authentication system. The device can receive authentication requests from the authentication system, perform verification actions, and submit responses, thereby eliminating the need for separate dedicated authentication hardware while maintaining security
Data Source
AI summary
Systems and methods for authorizing data transfers are disclosed. Exemplary implementations may: receive a data transfer authorization request based on a data transfer initiated by a customer computing device; when the customer computing device is associated with a system of trust: send a third-party second-factor authentication message to trustee computing device(s) without sending any message to the customer computing device, and authorize the data transfer system to complete the data transfer request in response to receipt of a third-party authentication confirmation from the trustee computing device(s) and in the absence of any authentication confirmation from the customer computing device.


