Unified Session Authentication Across Multiple Channels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication processes require users to separately authenticate to different communications channels, which is burdensome and time-consuming for both senders and receivers.
Innovation Solution
Implementing an authentication engine that recognizes active sessions across multiple communications channels, allowing users to authenticate using strong authentication on one channel and weak authentication, such as a challenge question, on another channel, enabling seamless access across various communication mediums.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate authentication is performed for each communications channel, then security is maintained through strong authentication on each channel, but user convenience deteriorates due to repeated authentication requirements
Solution Approach 1:
The patent merges authentication sessions across multiple communications channels by creating a unified session management system. When a user authenticates on one channel (e.g., voice channel), the authentication session is shared with other channels (e.g., data channel), eliminating the need for separate strong authentication on each channel while maintaining security through session validation.
Solution Approach 2:
The system performs preliminary strong authentication on the first communications channel, then reuses that authentication result for subsequent channels. The authentication engine pre-establishes trust relationships and session states that can be leveraged across channels, reducing the need for repeated authentication actions.
2Reliability
If strong authentication is required on every communications channel, then security is improved, but authentication time increases making the process time-consuming
Solution Approach 1:
The patent combines authentication sessions across communications channels so that strong authentication performed once can be reused. The authentication engine maintains session state that spans multiple channels, allowing users to authenticate strongly on one channel and then access other channels using the shared session without repeating the time-consuming strong authentication process.
Solution Approach 2:
The authentication session maintains continuity across channel transitions. Once authentication is established on one channel, the session state persists and can be utilized across different communications channels, ensuring continuous access without interruption or repetition of the authentication process.
3Adaptability or versatility
If multiple communications channels are supported, then system versatility is improved, but authentication complexity increases requiring separate authentication procedures
Solution Approach 1:
The authentication engine is designed with universal functionality to handle multiple communications channels through a unified authentication framework. It can manage sessions across voice channels, data channels, and other communication mediums using the same core authentication logic and session management mechanisms, reducing the need for channel-specific authentication implementations.
Solution Approach 2:
The system segments authentication management into distinct components: channel-independent session management and channel-specific access control. The authentication engine handles the complex session state management universally, while individual channels can implement simpler access rules based on the shared session information, reducing overall system complexity.
Data Source
AI summary
A user may access an institution system via more than one communications channel, either by the same device (e.g., a mobile device accessing the institution system via a voice channel and a data channel) or by different devices (e.g., a personal computer via a web channel and a phone via a voice channel). If a user is not currently authenticated to a communications channel and attempts to access the institution system via a communications channel, the user may be authenticated using strong authentication. If the user is currently authenticated to the institution system via a communications channel and would like to engage a second communications channel to access the institution system, the user may authenticate to the second communications channel using both communications channels and weak authentication, such as single factor authentication or a challenge question.


