Voucher Code Authentication for Tokenless User Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication systems require physical possession of an operative authentication token, which can lead to issues when the token is misplaced, forgotten, or unavailable due to battery depletion, and do not provide a secure method for authentication in such scenarios.
Innovation Solution
An authentication system that allows one user to vouch for another, providing a fourth authentication factor based on 'somebody the user knows,' enabling secure authentication without physical possession of the token, by generating a voucher code that can be used in conjunction with a PIN or tokencode for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional two-factor or three-factor authentication systems are used, then authentication security is maintained through physical token possession, but users cannot authenticate when the token is misplaced, forgotten, or unavailable
Solution Approach 1:
A voucher code acts as an intermediary that bridges the gap between the user and the authentication system when the primary token is unavailable. The voucher code, generated by an authenticated user (the vouching user), serves as a temporary credential that allows the second user to authenticate without physically possessing their own token. This intermediary mechanism resolves the contradiction by providing an alternative authentication path that maintains security while enabling access.
Solution Approach 2:
The system performs preliminary authentication by requiring a vouching user to authenticate first before generating a voucher code for another user. This preliminary action ensures that only authenticated users can create voucher codes, maintaining security while enabling subsequent authentication for users who have lost their tokens. The preliminary authentication step prevents unauthorized voucher code generation while still allowing legitimate access.
2Reliability
If a fourth authentication factor (vouching) is added to allow authentication without physical token possession, then authentication availability is improved, but system complexity increases
Solution Approach 1:
The voucher code mechanism serves multiple functions within the authentication system. It acts as a temporary credential, a security approval mechanism, and a fallback authentication method all in one. The same voucher code system can be used whether the user lost their token, forgot their PIN, or needs to authenticate from a new device. This multi-functionality reduces the need for separate systems for each scenario, thereby limiting the increase in overall system complexity while maintaining high authentication availability.
3Reliability
If voucher codes are generated and distributed to users, then authentication can proceed without physical token possession, but security risks may arise from unauthorized voucher code generation
Solution Approach 1:
The authentication server provides feedback by verifying the voucher code against the database before granting authentication. The server checks whether the voucher code is valid, not expired, and properly authorized. This feedback mechanism prevents unauthorized access because even if someone obtains a voucher code through improper means, the server's verification process will reject invalid codes. The feedback loop maintains security while enabling authentication continuity.
Solution Approach 2:
The system performs preliminary validation of the voucher code before granting authentication access. The authentication server checks the voucher code's validity, expiration status, and authorization level as a preliminary step before allowing the user to proceed. This preliminary action prevents unauthorized access by filtering out invalid voucher codes before they can be used for authentication, thereby maintaining security while enabling continuous authentication for legitimate users.
Data Source
AI summary
An authentication server authenticates a first user, and generates a voucher code that is provided to the authenticated first user. The first user may provide the voucher code to a second user, responsive to a request by the second user for the first user to vouch for the second user, to thereby allow the second user to be authenticated. The authentication server receives the voucher code from the second user, and authenticates the second user based on the voucher code. The authenticated second user may be provided with a temporary password or other type of code utilizable for at least one additional authentication.


