A system and method for generating renewable identities using an identity apparatus

The system generates renewable identities with dynamic personally identifiable information to protect against identity theft by regularly updating identity details, thereby enhancing security and preventing fraud.

WO2026033254A1PCT designated stage Publication Date: 2026-02-12YADAV RANJANA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2024/059411
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-06
Filing Date
2024-09-26
Publication Date
2026-02-12

AI Technical Summary

Technical Problem

Existing identity systems are vulnerable to various attacks, with personally identifiable information being immutable and easily compromised, leading to identity theft and related crimes.

Method used

A system and method for generating renewable identities using an identity apparatus with dynamic personally identifiable information (DPI) features, including a display unit for one-time partial and complete identities, an integrated circuit chip for secure data storage, and a power button for activating dynamic displays, along with a backend infrastructure for managing and authenticating identities.

Benefits of technology

The system effectively protects identities from attacks like card skimming and phishing by regularly updating identity information, enhancing security and preventing fraud.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2024059411_12022026_PF_FP_ABST
    Figure IB2024059411_12022026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed herein is an identity apparatus (100) with dynamic personally identifiable information (DPII) feature, comprising a first display unit (102) configured to display an identity number including, OTPI The identity apparatus (100) comprising a second display unit (104) configured to display dynamic expiry date. The identity apparatus (100) comprising a third display unit (106) configured to display a dynamic security code. The identity apparatus (100) comprising a power on / off button (108) having the operability characterized by keeping the first display unit (102), the second display unit (104) and the third display unit (106) switched off and blank in a 'power off' state and activating the first display unit (102), the second display unit (104) and the third display unit (106) in a 'power on' state. The identity apparatus (100) comprising an integrated circuit chip (110), a magnetic strip (112), and a plurality of identifier (114).
Need to check novelty before this filing date? Find Prior Art

Description

A SYSTEM AND METHOD FOR GENERATING RENEWABLE IDENTITIES USING AN IDENTITY APPARATUSFIELD OF DISCLOSURE

[0001] The present disclosure generally is a system for identity generation and specifically relates to system for generating and protecting renewable identities on identity cards from several types of attacks.BACKGROUND OF THE DISCLOSURE

[0002] Embodiments of the present invention generally relate to a system and method for generating renewable identities using an identity apparatus.

[0003] Offline and online identity theft, along with identity-related crimes, constitute serious threats to individuals, businesses, and governments worldwide. Offline identity theft occurs through traditional means, such as stolen wallets or documents, dumpster diving, and social engineering tactics like pretexting. Conversely, online identity theft exploits digital channels, including phishing emails, malware, fake websites, and data breaches, to steal personal information for fraudulent purposes.

[0004] Both forms of identity theft can lead to financial losses, damaged credit scores, legal troubles, and emotional distress for victims. Identity- related crimes encompass a broad spectrum of illegal activities, including identity cloning, synthetic identity fraud, account takeover fraud, tax fraud, and medical identity theft.

[0005] Such crimes undermine trust in institutions, disrupt services, and impose significant financial burdens on individuals and organizations. Preventing and addressing these threats requires a comprehensive approach, integrating technological solutions like encryption and multi-factor authentication with education and awareness campaigns to empower individuals to safeguard their personal information. Moreover, currentlythere are many security protocols, regulatory frameworks and laws for deterring and prosecuting perpetrators of identity-related crimes, and enhancing security and protecting individuals' rights in an increasingly digital world.

[0006] However, the existing techniques are only partially successful in preventing and mitigating the risks associated with offline and online identity theft and identity-related crimes. An examination of multiple fraudulent situations reveals a basic weakness in every identity system on the planet - the private information about an individual is immutable and is printed on the ID card for an extended period of time. Once compromised, the information can be sold on the Dark Web or used improperly to initiate other types of assaults.

[0007] Therefore, there is a need for a more dynamic approach to protect the crucial information related to personal identities. Further, there is need for system which cannot be compromised by means of phishing, vishing, smishing, pharming, Man-ln-The-Middle (MITM), card skimming, photo copy fraud, insider fraud, shoulder surfing, SIM switching, and others.

[0008] Therefore, there is a need of a system and method for generating renewable identities.SUMMARY

[0009] The following is a summary description of illustrative embodiments of the invention. It is provided as a preface to assist those skilled in the art to more rapidly assimilate the detailed design discussion which ensues and is not intended in any way to limit the scope of the claims which are appended hereto in order to particularly point out the invention.

[0010] Embodiments in accordance with the present invention provide an identity apparatus with dynamic personally identifiable information (DPI I) feature. Embodiments in accordance with the present invention also provide to a computer-implemented system of generating renewable identities usingan identity apparatus. Embodiments in accordance with the present invention further provide a system for generating renewable identities using an identity apparatus.

[0011] Embodiments of the present invention may provide a number of advantages depending on its particular configuration. First, embodiments of the present application provide an identity apparatus with dynamic personally identifiable information (DPI I) feature. Next, a system of generating renewable identities using an identity apparatus. Next, to a method for generating renewable identities using an identity apparatus

[0012] The present disclosure solves all the major limitation of traditional systems.

[0013] An objective of present disclosure is to protect personally identifiable information (PH) on identity cards from several types of attacks.

[0014] Another objective of the present disclosure is to develop a system and method of renewable identities that will prevent a variety of assaults, including card skimming, phishing, smishing, vishing, photocopy fraud and so.

[0015] Another objective of present disclosure is to safeguard the renewable "online" and "real world / physical" identities from various attacks.

[0016] Another objective of present disclosure is to generate partial and complete identity information.

[0017] Another objective of present disclosure is to develop a system of generating renewable identities that can be used by various organizations such as banks, government bodies issuing passport, driving licenses, national identities, voter ID cards, and so.

[0018] Another objective of the present invention is to provide an interface which comprises generating Dynamic Partial Identity to remove static Personally Identifiable Information (PH).

[0019] Another objective of the present invention is to provide an apparatus which presents one or more dynamic interfaces.

[0020] Another objective of the present invention is to provide an authentication mechanism for the relying parties who consume these identities. Upon successful authentication, the Identity provider software derives Complete Identity which are mapped to relying parties.

[0021] Yet another objective of the present disclosure, is to protect online identities such as, username.

[0022] Yet another objective of the present disclosure, is to generate and protect dynamic identity data.

[0023] In light of above disclosure, in an aspect of the present invention an identity apparatus with dynamic personally identifiable information (DPI I) feature is disclosed herein. The identity apparatus comprising a first display unit on the identity apparatus and the first display unit configured to display an identity number including, a one-time partial identity (OTPI) or a partial identity (PID). The identity apparatus also comprising a second display unit on the identity apparatus and the second display unit configured to display dynamic expiry date of the one-time complete identity (OTCI). The identity apparatus also comprising a third display unit on the identity apparatus and the third display unit configured to display a dynamic security code. The identity apparatus also comprising a power on / off button installed on the identity apparatus and the power on / off button having the operability characterized by keeping the first display unit, the second display unit and the third display unit switched off and blank in a ‘power off’ state, and activating the first display unit, the second display unit and the third display unit in a ‘power on’ state. The identity apparatus also comprising an integrated circuit chip installed on the surface of the identity apparatus and the integrated circuit chip configured to store identity related sensitive data such as shared secret keys. The identity apparatus also comprising a plurality of identifier etched or printed on the identity apparatus and the identifiers include, a name, a photograph, a signature, name of the issuer,and account number.

[0024] In another aspect of the present invention a system of generating renewable, dynamic and secure identities is disclosed herein. The system comprising an identity provider (IDP) module configured to generate a new identity number, an expiry date, and a security code after a predetermined threshold time interval, manage user identities and authentication, and decide the expiry date of each unique one-time complete identity (OTCI) that is different for different end user. The end user has several one-time complete identity (OTCI) in the identity provider module. The system also comprising a backend infrastructure operationally coupled to the identity provider (IDP) module and the backend infrastructure configured to support the operation of the identity provider (IDP) module. The system also comprising a database operationally coupled to the backend infrastructure and the database configured to securely store user credential related information such as shared secret keys, configuration settings, and generated identity logs. The system also comprising a security key generator operationally coupled to the identity provider (IDP) module and the security key generator configured to generate a first shared secret key (SS1), a second shared secret key (SS2), and a third shared secret key (SS3). The system also comprising a communication protocol module linked to the identity provider (IDP) module and the communication protocol module configured to establish communication between the identity provider (IDP) module. The system also comprising an end user interface operationally coupled to the communication protocol module and the end user interface configured to generate and display a one-time partial identity (OTPI). The new identity number as generated by the identity provider (IDP) module and end user interface is divided into at least two logical blocks further having a first logical block (B1 ) and a second logical block (B2) and the security code generated by end user interface is a third logical block (B3). The values of the second logical block (B2) and third logical block (B3) changes simultaneously due to synchronization of time intervals. The partial identity information displayed on the end user interface as a partial identity(RID). The partial identity information displayed on the end user interface is dynamic and time bound. The validation module operationally coupled to the end user interface and relying party interface and the identity provider (IDP) module and the validation module configured for comparing the security code received from the relying party interface and matches the one that identity provider (IDP) calculated by the identity provider (IDP) module, and successful validation if the incoming security code matches the one that identity provider (IDP) module has calculated. The system also comprising a relying party operationally coupled to the communication protocol module and the validation module and the relying party interface configured to receive a one-time complete identity (OTCI) generated by the identity provider (IDP) module, and authenticate the end user to the identity provider module server. The complete end user authentication transaction requires one-time complete identity (OTCI) information from identity provider module server. The identity provider module 202 may deliver the one-time complete identity (OTCI) and expiry date to the end user or relying party 216 or both.

[0025] In one embodiment, the identity provider (IDP) module generates the new identity number in form a one-time complete identity (OTCI) value based on a time interval and a shared secret key as generated by the security key generator.

[0026] In one embodiment, the end user interface is further linked to a mobile application to facilitate user authentication.

[0027] In one embodiment, the frequency at which the identity information displayed on the end user interface changes, vary from one second to several years.

[0028] In one embodiment, some or all of the identity information displayed on the end user interface produces unique and non-repeatable one time partial identity (OTPI) after a defined time interval.

[0029] The system also comprising a method for generating renewable, dynamic and secure identities. The method includes turning ‘on’ a poweron / off button on an identity apparatus or an end user interface and displaying a partial identity (PID) or a one-time partial identity (OTPI), an expiry date, and a security code respectively on a first display unit, a second display unit, and a third display unit. The method also includes sending the partial identity (PID) or a one-time partial identity (OTPI), the expiry date, and the security code displayed to a relying party, which in turn, communicates with identity provider (IDP) module for authentication and obtaining a one-time complete identity (OTCI). The identity provider module also delivers a part of one-time complete identity (OTCI) to relying party. The method also includes using a first logical block (B1 ) for identifying the user by the identity provider (IDP) module. The method also includes computing and validating a third logical block (B3) based on the received security code using a third shared secret key (SS3). The method also includes verifying the incoming expiry date via a validation module and if it matches with logic of the identity provider (IDP) module expiry date, the validation is successful. The method also includes computing a second logical block (B2) based on the received one-time partial identity (OTPI) using a second shared secret key (SS2) after successful validation. For validation the second logical block (B2) is computed at the identity provider (IDP) module using a predetermined protocol and a time interval synchronized with the identity apparatus. The method also includes appending the second logical block (B2) to the received one-time partial identity (OTPI) to generate a one-time complete identity (OTCI). The method also includes returning the generated one-time complete identity (OTCI) via the identity provider (IDP) module to relying party to complete an end-user transaction. The identity provider (IDP) module and identity apparatus maintain time counter for measuring or counting time. The identity provider (IDP) module and identity apparatus maintain same set of shared secret keys and time counter leveraged by producing Identity information.

[0030] In one embodiment, the mapping of unique one-time complete identity (OTCI) to relying parties further comprises allotting every one of therelying party a relying party identity (RPI) that is a unique identity mapping each one-time complete identity (OTCI) against relying party identity (RPI) by the identity provider module to track misuse of identities, and storing onetime complete identity (OTCI) as stored one time complete identity (SOTCI) by the relying party.

[0031] In one embodiment, the relying party leveraging stored one time complete identity (SOTCI) for executing a transaction and the identity provider module validating the usage further comprises mapping the unique stored one time complete identity (SOTCI) with the relying party identity (RPI) by the identity provider module, checking if the stored one time complete identity (SOTCI) with the relying party identity (RPI) and allowing transaction if a match occurs, and declining transaction if the stored one time complete identity (SOTCI) mismatches with the relying party identity (RPI) and preventing potential fraud.

[0032] In one embodiment, the method also provides dynamic end user authentication including obtaining a dynamic username by the one time partial identity (OTPI) from the end user interface as a one time username (OTUN), and using the security code (B3) as a dynamic password.

[0033] These and other advantages will be apparent from the present application of the embodiments and solves abovementioned limitations in the traditional system.

[0034] The preceding is a simplified summary to provide an understanding of some embodiments of the present invention. This summary is neither an extensive nor exhaustive overview of the present invention and its various embodiments. The summary presents selected concepts of the embodiments of the present invention in a simplified form as an introduction to the more detailed description presented below. As will be appreciated, other embodiments of the present invention are possible utilizing, alone or in combination, one or more of the features set forth above or described in detail below.

[0035] These elements, together with the other aspects of the present disclosure and various features are pointed out with particularity in the claims annexed hereto and form a part of the present disclosure. For a better understanding of the present disclosure, its operating advantages, and the specified object attained by its uses, reference should be made to the accompanying drawings and descriptive matter in which there are illustrated exemplary embodiments of the present disclosure.BRIEF DESCRIPTION OF THE DRAWINGS

[0036] The above and still further features and advantages of embodiments of the present invention will become apparent upon consideration of the following detailed description of embodiments thereof, especially when taken in conjunction with the accompanying drawings, and wherein:

[0037] FIG. 1A illustrates a block diagram showcasing all the components of an identity apparatus with dynamic personally identifiable information (DPI I) feature, according to an embodiment of the present invention;

[0038] FIG. 1 B illustrates the front view of the proposed identity apparatus components, according to an embodiment of the present invention;

[0039] FIG. 1C illustrates the rear view of the proposed identity apparatus components, according to an embodiment of the present invention;

[0040] FIG. 1 D illustrates the front and rear view of the proposed identity apparatus components in a power-off state, according to an embodiment of the present invention;

[0041] FIG. 1 E illustrates the front and rear view of the proposed identity apparatus components in a power-on state, according to an embodiment of the present invention;

[0042] FIG. 2A illustrates a block diagram of a computer-implemented system of generating renewable, dynamic and secure identities, accordingto an embodiment of the present invention;

[0043] FIG. 2B illustrates a front view of the proposed end user interface in form of an an identity apparatus representing a plurality of logical block, according to an embodiment of the present invention;

[0044] FIG. 2C illustrates a rear view of the proposed end user interface in form of an an identity apparatus representing a logical block, according to an embodiment of the present invention;

[0045] FIG. 2D illustrates the proposed Identity apparatus with 16-digit identity number and partial identity (PID), according to an embodiment of the present invention;

[0046] FIG. 2E illustrates the proposed Identity apparatus with 18-digit identity number and two logical blocks, according to an embodiment of the present invention;

[0047] FIG. 2F illustrates the proposed Identity apparatus with 18-digit identity number and partial identity (PID), according to an embodiment of the present invention;

[0048] FIG. 3A illustrates a flowchart of a method for generating renewable, dynamic and secure identities, according to an embodiment of the present invention;

[0049] FIG. 3B illustrates a block diagram for an exemplary PID Transaction at T=0 min, according to an embodiment of the present invention;

[0050] FIG. 3C illustrates a block diagram for an exemplary PID Generic Transaction Account mapping depicting general situation in which the account number and OTCI are obtained by the relying party, according to an embodiment of the present invention;

[0051] FIG. 4 illustrates a block diagram for an exemplary PID Transaction at T= 5 min, according to an embodiment of the present invention;

[0052] FIG. 5A illustrates a block diagram for an exemplary proposed identity apparatus with 18 Digit PAN number and three blocks, according to an embodiment of the present invention;

[0053] FIG. 5B illustrates a block diagram for an exemplary PID and OTCI Transaction at T = 365 Days (beginning of 2ndyear), according to an embodiment of the present invention;

[0054] FIG. 5C illustrates a block diagram for an exemplary prevention of a bad actor from fetching Complete Identity, according to an embodiment of the present invention;

[0055] FIG. 5D illustrates a block diagram for an exemplary relying party obtains the OTCI and account number in a banking payment transaction, according to an embodiment of the present invention

[0056] FIG. 5E illustrates a block diagram for an exemplary PID and OTCI Banking (Payment) Transaction, according to an embodiment of the present invention;

[0057] FIG. 5F illustrates a block diagram for an alternative exemplary approach of OTPI and OTCI Banking (Payment) Transaction, according to an embodiment of the present invention;

[0058] FIG. 5G illustrates a block diagram for an exemplary partial identity mapping with end user account number, according to an embodiment of the present invention; and

[0059] FIG. 5H illustrates a block diagram for an exemplary stored OTCI (SOTCI) validation transaction, according to an embodiment of the present invention.

[0060] The headings used herein are for organizational purposes only and are not meant to be used to limit the scope of the description or the claims. As used throughout this application, the word "may" is used in a permissive sense ( / .e., meaning having the potential to), rather than the mandatorysense ( / .e., meaning must). Similarly, the words “include”, “including”, and “includes” mean including but not limited to. To facilitate understanding, like reference numerals have been used, where possible, to designate like elements common to the figures. Optional portions of the figures may be illustrated using dashed or dotted lines, unless the context of usage indicates otherwise.DETAILED DESCRIPTION

[0061] The following description includes the preferred best mode of one embodiment of the present invention. It will be clear from this description of the invention that the invention is not limited to these illustrated embodiments but that the invention also includes a variety of modifications and embodiments thereto. Therefore, the present description should be seen as illustrative and not limiting. While the invention is susceptible to various modifications and alternative constructions, it should be understood, that there is no intention to limit the invention to the specific form disclosed, but, on the contrary, the invention is to cover all modifications, alternative constructions, and equivalents falling within the spirit and scope of the invention as defined in the claims.

[0062] In any embodiment described herein, the open-ended terms "comprising," "comprises,” and the like (which are synonymous with "including," "having” and "characterized by") may be replaced by the respective partially closed phrases "consisting essentially of," consists essentially of," and the like or the respective closed phrases "consisting of," "consists of, the like.

[0063] As used herein, the singular forms “a”, “an”, and “the” designate both the singular and the plural, unless expressly stated to designate the singular only.

[0064] FIG. 1A illustrates a block diagram showcasing the components of an identity apparatus 100 with dynamic personally identifiable information (DPI I) feature, according to an embodiment of the present invention.

[0065] The identity apparatus 100 may be comprising a first display unit 102, a second display unit 104, a third display unit 106, a power on / off button 108, an integrated circuit chip 110, a magnetic strip 112, and a plurality of identifiers 114.

[0066] The first display unit 102 may be on the identity apparatus 100 and the first display unit 102 configured to display an identity number including, a one-time partial identity (OTPI) or a partial identity (PID).

[0067] The second display unit 104 may be on the identity apparatus 100 and the second display unit 104 configured to display dynamic expiry date of the one-time complete identity (OTCI).

[0068] The third display unit 106 may be on the identity apparatus 100 the third display unit 106 configured to display a dynamic security code.

[0069] The power on / off button 108 may be installed on the identity apparatus 100 and the power on / off button 108 having the operability characterized by keeping the first display unit 102 and the second display unit 104 and the third display unit 106 switched off and blank in a ‘power off’ state, and activating the first display unit 102 and the second display unit 104 and the third display unit 106 in a ‘power on’ state.

[0070] The integrated circuit chip 110 may be installed on the surface of the identity apparatus 100 and the integrated circuit chip 110 configured to store identity related sensitive data such as shared secret keys.

[0071] The plurality of identifier 114 may be on the surface of the identity apparatus 100 and the identifiers 114 include, a name, a photograph, a signature, name of the issuer, and account number.

[0072] In a preferred embodiment, the identity apparatus may be a smart interface or a smart card capable of being charged using rechargeable or non-rechargeable sources of power. Embodiment of the present invention are intended to cover or otherwise include suitable chargeable smart card including, known, related art, and / or later developed technologies.

[0073] In a preferred embodiment, the first display unit 102, the second display unit 104, and the third display unit 106 may be a light emitting diode (LED) screen. Embodiment of the present invention are intended to cover or otherwise include various types of display unit including, known, related art, and / or later developed technologies.

[0074] FIG. 1 B illustrates the front view of the proposed identity apparatus 100 components, according to an embodiment of the present invention.

[0075] FIG. 1C illustrates the rear view of the proposed identity apparatus 100 components, according to an embodiment of the present invention.

[0076] In an embodiment of the present disclosure, the dynamic personally identifiable information (DPI I) may include an identity number and an expiry date that renews after a fixed time interval. The identity number may vary as often as the issuing authority chooses and its security posture may determine the ‘time interval’ for which the identity number is valid. For an instance, if the time interval is determined to be at five minutes, the identity number will be reset every five minutes. In an embodiment of the present disclosure, the organisations that truly provide identity to the end user may be known as issuing authorities. These may include banks (for debit and credit cards), passport offices, Department of motor and transport (for driving licences), private enterprises (for employee IDs), retail stores (for loyalty cards), and such.

[0077] In some embodiments, every identity displayed may be valid for predetermined number of months. In some embodiments, the time interval may range a few minutes to several years. For an instance, each user may have a different expiry date such as, three years, two years and so, which may make it more difficult for dishonest actors to estimate these numbers and impersonate the victims when there may be variable expiry dates.

[0078] In an embodiment of the present disclosure, when the power on / off button 108 may be pressed on, both the identity number and the expiry date may be shown on the first display unit 102 and the second display unit 104.In a preferred embodiment, the identity apparatus 100 may enter powersaving mode after a pre-specified time, for example two minutes. If the button may be pushed again within a pre-defined threshold time, for example, 5 minutes, the first display unit 102 and the second display unit 104 may still display the same values.

[0079] In some embodiments, the power on / off button 108 may also be configured with biometrics to provide an extra layer of authentication, depending on the issuing authority. For an instance, a biometric finger print may be taken at registration, and the identity apparatus 100 may only unlock with the proper biometrics. When the identity apparatus 100 is issued, biometric finger prints may be used for deduplication purposes, this provides a way to unlock the identity apparatus 100. Biometrics will guarantee that counterfeiting of the identity apparatus 100 may never function and may serve as a deterrent to theft. In some embodiments, a PIN may be used to authenticate the user and unlock the identity apparatus 100.

[0080] In an embodiment of the present disclosure, the security code displayed on the third display unit 106 on the identity apparatus 100 may change in tandem with every new identity number generated. In some embodiments, the issuing authority may be able to customize the change frequency to suit their security requirements. For an instance, the security code may renew every five minutes.

[0081] FIG. 1 D illustrates the front and rear view of the proposed identity apparatus 100 components in a power-off state, according to an embodiment of the present invention.

[0082] FIG. 1 E illustrates the front and rear view of the proposed identity apparatus 100 components in a power-on state, according to an embodiment of the present invention.

[0083] In an embodiment of the present disclosure, the power on / off button 108 when pressed ‘on’, may enable the first display unit 102 to display a Partial Identity Number (PID) rather than a complete identity number. In apreferred embodiment, some pre-determined digits of the identity number may be obscured as For an instance the first display unit 102 may display the identity number - 4838 2769 8348 ****. In this example, the final four numbers may be shown on the interface / screen as

[0084] FIG. 2A illustrates a block diagram of computer-implemented system 100 of generating renewable, dynamic and secure identities, according to an embodiment of the present invention.

[0085] The system 200 comprising an identity provider (IDP) module 202, a backend infrastructure 204, a database 206, a security key generator 208, a communication protocol module 210, an end user interface 212, a relying party interface 216 and a validation module 214.

[0086] The identity provider (IDP) module 202 configured to generate a new identity number, an expiry date, and a security code after a predetermined threshold time interval, manage user identities and authentication, and decide the expiry date of each unique one-time complete identity (OTCI) that is different for different end user. The end user has several one-time complete identity (OTCI) in the identity provider module 202.

[0087] The backend infrastructure 204 operationally coupled to the identity provider (IDP) module 202 and the backend infrastructure 204 configured to support the operation of the identity provider (IDP) module 202.

[0088] The database 206 operationally coupled to the backend infrastructure 204 and the database 206 configured to securely store user credential related information such as shared secret keys, configuration settings, and generated identity logs.

[0089] The security key generator 208 operationally coupled to the identity provider (IDP) module 202 and the security key generator 208 configured to generate a first shared secret key (SS1), a second shared secret key (SS2), and a third shared secret key (SS3).

[0090] The communication protocol module 210 linked to the identityprovider (IDP) module 202 and the communication protocol module 210 configured to establish communication between the identity provider (IDP) module 202.

[0091] The end user interface 212 operationally coupled to the communication protocol module 210 and the end user interface 212 configured to generate and display a one-time partial identity (OTPI). The new identity number as generated by the identity provider (IDP) module 202 and end user interface 212 may be divided into at least two logical blocks further having a first logical block (B1 ) and a second logical block (B2) and the security code generated by end user interface 212 is a third logical block (B3). The values of the second logical block (B2) and third logical block (B3) may change simultaneously due to synchronization of time intervals. The partial identity information may be displayed on the end user interface 212 as a partial identity (PID). The partial identity information displayed on the end user interface 212 may be dynamic and time bound.

[0092] The validation module 214 may be operationally coupled to the end user interface 212, relying party interface 216 and the identity provider (IDP) module 202 and the validation module 214 configured for comparing the security code received from the relying party interface 216 and matches the one that identity provider (IDP) calculated by the identity provider (IDP) module 202 and successful validation if the incoming security code matches the one that identity provider (IDP) module 202 has calculated.

[0093] The relying party 216 may be operationally coupled to the communication protocol module 210 and the validation module 214 and the relying party interface 216 configured to receive a one-time complete identity (OTCI) generated by the identity provider (IDP) module. The complete end user authentication transaction may require one-time complete identity (OTCI) information from identity provider module 202 server. The identity provider module 202 may deliver the one-time complete identity (OTCI) and expiry date to the end user or relying party 216 or both

[0094] The identity provider (IDP) module 202 may generate the newidentity number in form a one-time complete identity (OTCI) value based on a time interval and a shared secret key as generated by the security key generator 208.

[0095] The end user interface 212 may be further linked to a mobile application to facilitate user authentication.

[0096] The frequency at which the identity information displayed on the end user interface (212) may change, vary from one second to several years.

[0097] Some or all of the identity information displayed on the end user interface (212) may produce unique and non-repeatable one time partial identity (OTPI) after a defined time interval.

[0098] In a preferred embodiment, the identity number returned by the identity provider (IDP) module 202 only appears once, it also termed as the one-time complete identity (OTCI) and if the partial identity number (PID) only appears once, it is also termed as one-time partial identity (OTPI). In an embodiment of the present disclosure, the communication protocol 210 may enable all communication over mutual Transport Layer Security (mTLS), which encrypts data while it is in transit. Embodiments of the present disclosure are intended to cover or otherwise include other suitable secure data communication protocols including, known, related art and later developed technologies.

[0099] In an embodiment of the present disclosure, the end user interface 212 may be an identity apparatus 100. In a preferred embodiment, the end user interface 212 may be a smart card.

[0100] In an embodiment of the present disclosure, the Identity Provider (IDP) module 202 may be software capable to function as the core component responsible generating renewable identities, managing user identities and authentication within the system 200, authentication of a plurality of end user interface 212 and relying parties to facilitate seamless authentication flows. In an embodiment of the present disclosure, theIdentity Provider (I DP) module 202 may incorporates advanced security measures such as encryption, multi-factor authentication, and threat detection to safeguard against identity-related risks and unauthorized access.

[0102] In an embodiment of the present disclosure, the backend infrastructure 204 may include robust and scalable servers, network components responsible for managing user identities, authentication requests, and security policies, advanced monitoring and logging mechanisms track system activities for compliance and security purposes, backup and disaster recovery measures ensure data integrity and continuity of service and more. In an embodiment of the present disclosure, the database 206 may be, but not limited to, a centralised database, a distributed database, an operational database, a relational database, a cloud database, an object-oriented database, blockchain-based database and so on.

[0103] In some embodiment, the security key generator 208 may use various techniques including, Pseudorandom Number Generation, Key Derivation Functions, Key Exchange Protocols, Quantum Key Distribution, Secure Element-based Key Generation, Biometric Key Generation and such. In some embodiments, the validation module 214 may use multi-factor authentication such as biometric verification. The validation module 214 may also track user sessions to prevent unauthorized access and maintain session integrity, perform audit logging and reporting, and ensure interoperability with external entities while maintaining security and data privacy.

[0104] FIG. 2B illustrates a front view of the proposed end user interface 212 in form of an identity apparatus 100 representing a plurality of logical block, according to an embodiment of the present invention.

[0105] FIG. 2C illustrates a rear view of the proposed end user interface 212 in form of an identity apparatus 100 representing a logical block, according to an embodiment of the present invention.

[0106] From here on, the mobile application may also be referred to as mobile app and function of the mobile application is discussed later. In a preferred embodiment, the shared secret keys as generated by the security key generator 208 may be mapped by the identity provider (IDP) module 202 to each logical block of the generated identity number. Each logical block may be associated with one or more unique shared secret key stored securely in the apparatus

[0107] In a preferred embodiment, the identity apparatus 100 may be divided into two logical parts. For an instance, for the identity number 4838 276983488475, the first logical block (B1 ) is 698348 and the second logical block B2 is 847. In an embodiment of the present disclosure, the number of bits for each logical block may vary. In an embodiment of the present disclosure, the logical blocks may be any numerical, alphabets or special characters.

[0108] In a preferred embodiment, a shared secret (SS) key may correspond to each of the logical blocks. For an instance, the first logical block (B1 ) may correspond to the first shared secret key (SS1 ), the second logical bock (B2) with the second shared secret key (SS2), and the third logical block (B3) with the third shared secret key (SS3).

[0109] In an embodiment of the present disclosure, the identity apparatus 100 may be federal information processing standard (FlPS)-certified to ensure that the shared keys generated by the security key generator 208 may be stored securely and may not be exportable. In a preferred embodiment, the first shared secret key (SS1 ), the second shared secret key (SS2), and the third shared secret key (SS3) may be Advanced Encryption Standards (AES) keys. In an embodiment of the present disclosure, the identical shared secrets may likewise be mapped to specific user account in the identity provider (IDP) module 202 and safely kept in an encrypted database supported by FIPS-certified Hardware Security Modules (HSM). In an embodiment of the present disclosure, the third logical block and corresponding shared security key may be stored safelyin the identity apparatus 100 and the identity provider (IDP) module 202, and database 206.

[0110] FIG. 2D illustrates the proposed Identity apparatus 100 with 16-digit identity number and partial identity (PID), according to an embodiment of the present invention.

[0111] In an exemplary embodiment, the identity number generated may have sixteen digits with the first block (B1 ) of six digits, and the second block (B2) of three digits. Initially, the identity apparatus 100 displays a Partial Identity (PID) (4838 2769 8348 ***5), when the user presses ‘on’ the power on / off button 108. The PID may be all that the malicious actor will learn in a Man-in-the-Middle attack because the identity apparatus 100 does not display the complete identity number. One effective attack vector for determining the full identity number and completing a Card-Not-Present (CNP) transaction may be a brute force attack. The likelihood of accurately guessing a three-digit number in a single try, where each digit can be any number from 0 to 9, is 0.1%. Thus, in comparison to statically printed Identity number, the proposed invention is 99.9% secure. Further, depending on the Issuing Authority’s policy, an account may be blocked after three unsuccessful tries. The likelihood of accurately guessing the actual the identity number in three tries is 0.3%. In this case, the method is 99.7% secure.

[0112] FIG. 2E illustrates the proposed Identity apparatus 100 with 18-digit identity number and two logical blocks, according to an embodiment of the present invention.

[0113] FIG. 2F illustrates the proposed Identity apparatus 100 with 18-digit identity number and partial identity (PID), according to an embodiment of the present invention.

[0114] In another exemplary embodiment, the identity number generated may have eighteen digits with the first block (B1 ) of seven digits, and the second block (B2) of four digits, where the one-time partial identity (OTPI)is 5849 3979 6061 **** *4 or the one-time complete identity (OTCI) is 5849 39796061 278554. In an embodiment of the present disclosure, the system 200 may support identity number of variable length. From here on, the expiry date may also be termed as expiration date or expiry.

[0115] Initially, the partial identity number (PID) may be (5849 3979 60612 **** 4) appears on the identity apparatus 100, in a ‘on’ state. It is 0.01 % likely that a 4-digit number may be properly guessed in a single try. As a result, the solution is 99.99% secure in comparison to the traditional identity systems in place today. The likelihood of accurately guessing the actual Identity Number in three tries is 0.03%. In this case, the system 200 is 99.97% secure.

[0116] FIG. 3A illustrates a flowchart of a method 300 for generating renewable, dynamic and secure identities, according to an embodiment of the present invention. The method 300 may comprise following steps.

[0117] At 302, turning ‘on’ a power on / off button 108 on an identity apparatus 100 or an end user interface 212 and displaying a partial identity (PID) or a one-time partial identity (OTPI), an expiry date, and a security code respectively on a first display unit 102, a second display unit 104, and a third display unit 106.

[0118] At 304, sending the partial identity (PID) or a one-time partial identity (OTPI), the expiry date, and the security code displayed to a relying party 216, which in turn, communicates with identity provider (IDP) module 202 for authentication and obtaining a one-time complete identity (OTCI). The identity provider module 202 may deliver a part of one-time complete identity (OTCI) relying party 216.

[0119] At 306, using a first logical block (B1 ) for identifying the user by the identity provider (IDP) module 202.

[0120] At 308, computing and validating a third logical block (B3) based on the received security code using a third shared secret key (SS3).

[0121] At 310, verifying the incoming expiry date via a validation module 214 and if it matches with logic of the identity provider (IDP) module 202 expiry date, the validation is successful.

[0122] At 312, computing a second logical block (B2) based on the received one-time partial identity (OTPI) using a second shared secret key (SS2) after successful validation. The second logical block (B2) is computed at the identity provider (IDP) module 202 using a predetermined protocol and a time interval synchronized with the identity apparatus 100.

[0123] At 314, appending the second logical block (B2) to the received onetime partial identity (OTPI) to generate a one-time complete identity (OTCI).

[0124] At 316, returning the generated one-time complete identity (OTCI) via the identity provider (IDP) module 202 to relying party to complete an end-user transaction. The identity provider (IDP) module 202 and identity apparatus 100 maintains time counter for measuring or counting time. The identity provider (IDP) module 202 and identity apparatus 100 maintain same set of shared secret keys and time counter leveraged for producing Identity information.

[0125] The mapping of unique one-time complete identity (OTCI) to relying parties may further comprise allotting every one of the relying parties 216 a relying party identity (RPI) that is a unique identity, mapping each one-time complete identity (OTCI) against relying party identity (RPI) by the identity provider module 202 to track misuse of identities, and storing one-time complete identity (OTCI) as stored one time complete identity (SOTCI) by the relying party 216.

[0126] The relying party 216 leveraging stored one time complete identity (SOTCI) for execute a transaction and the identity provider module 202 validating the usage may further comprise mapping the unique stored one time complete identity (SOTCI) with the relying party identity (RPI) by the identity provider module 202, checking if the stored one time complete identity (SOTCI) with the relying party identity (RPI) and allowing transactionif a match occurs, and declining transaction if the stored one time complete identity (SOTCI) mismatches with the relying party identity (RPI) and preventing potential fraud.

[0127] The method 300 may also provide dynamic end user authentication includes obtaining a dynamic username by the one time partial identity (OTPI) from the end user interface 212 as a one time username (OTUN); and using the security code (B3) as a dynamic password.

[0128] Fig 3B illustrates a block diagram for an exemplary PID Transaction at T=0 min, according to an embodiment of the present invention.

[0129] FIG. 3C illustrates a block diagram for an exemplary PID Generic Transaction Account mapping depicting general situation in which the account number and OTCI are obtained by the relying party, according to an embodiment of the present invention.

[0130] In a preferred embodiment, various categories of legitimate entities that essentially require retrieving the identity information from identity apparatus 100 incudes the end user or identity holder, a broker or an agent who gathers identification data on behalf of the final user and provides it to the relying party, security personnel, such as police, immigration inspectors, and so, and relying party who consume these identities for example Airlines, hotel, banks, service providers and so. In some embodiments, a broker or an agent may be a travel agency gathering client data and providing it to hotels, airlines, and other establishments.

[0131] In an embodiment of the present disclosure, the Partial Identity (PID), the Expiry date, and the Security code may be shown on the identity apparatus 100 with a single button push of the power on / off button 108. The concerned entity may connect with identity provider (IDP) module 202 in order to obtain the full Identity. The identity number and security code changes after a predetermined threshold time interval, such as five minutes. In some embodiments, the predetermined threshold time interval may vary as per the requirement.

[0132] Fig. 4 illustrates a block diagram for an exemplary PID Transaction at T= 5 min, according to an embodiment of the present invention.

[0133] The process 400 for computing the second logical block (B2) at the identity provider module 202 includes computing the first value (V1 ) which is a hash value produced using a cryptographic algorithm such as HMAC- SHA256 that incorporates the second secret key (SS2) in the hashing process, truncating the first value (V1 ) to obtain a second value (V2), and computing a third value (V3) as the d-least significant base-10 digits of the second value (V2);

[0134] The process 400, for many years, have been used to manage dynamic passwords but never for securing identity information that are dynamic. This highlights the significant improvement on prior art and novel aspects of the suggested system.

[0135] The second logical block (B2) may be computed at the identity provider (IDP) module 202 using a predetermined protocol and a time interval synchronized with the identity apparatus 100 or the end user interface 212.

[0136] The values of the second logical block (B2) and third logical block (B3) may change simultaneously due to synchronization of time intervals.

[0137] From here on, the identity number will (also be referred to as identity or ID or Complete ID (CID). In a preferred embodiment, the identity apparatus 100 may have the one-time partial identity (OTPI) stored prior to authentication and computing at the identity provider (IDP) module 202. When logical Block (B2) is appended to the one-time partial identity (OTPI), one-time complete identity (OTCI) is ready to be shipped.

[0138] In an exemplary embodiment, initially at T= 0 the identity apparatus may display a partial identity number (PID) =4838 2769 8348 **** and at T= 5 minutes (after 5 minutes) and validation, the end user interface 212 or the identity apparatus displays the same identity number i.e. (PID) =4838 27698348 ****. If the end user authenticates twice or more within these 5 minutes, the PID / OTPI displayed may still be 4838 2769 8348 8475. In a preferred embodiment, the returned values of the identity number may change only after defined time interval. In some embodiments the user can have multiple unique OTCI associated at any given point in time and each OTCI will have its expiry decided by the Issuing Authority and such unique OTCIs may be tied to respective Relying Parties who consume these identities.

[0139] In an exemplary embodiment, the issuing authority may be a bank that would like to retain the generated identity number in a static state for an extended period of time, say five years, as comparable to the current system of issuing five-year bank cards. In order to accomplish this embodiment, the time interval for the second logical block (B2) may be set to five years. Consequently, upon successful authentication by any Relying Party (RP), the identity provider (I DP) module 202 may always return the same identity number, which can be referred to as Complete ID (CID). One feature of CID may be that there will only be one CID associated with each user account.

[0140] However, it can be challenging to identify and isolate the culpable RP when several RPs share the same CID, or fraudulent administrator commits fraud leading to Card skimming or RP may be compromised. CID may also be prone to replay attack. To counter this challenge, the present invention proposes OTCI expiry dates which may be dynamic instead of being static as the pre-determined expiry dates in the traditional identity cards. One of the significant advantages of this strategy may be that PID can be cached on payment websites or mobile apps as it is currently done, and relying parties can get OTCI or CID when needed. Thus, convenient for the endusers. Even if the PID may be captured by malicious actors as it stays static for a long time. However, security codes may change every few minutes and expiry dates may be unpredictable, which makes it hard for malicious actor to predict security codes and expiry dates.

[0141] In an embodiment of the present disclosure, the process of relying party authenticating itself to the identity provider (IDP) module 202 may be done in three ways including, by a natural person, by a banking merchant, and by a generic machine-to-machine. In some embodiments, the natural person may be any human, including identity holder or relying parties like brokers, agents, Security Officers (SO), and even MITM hackers who require Complete ID to perpetrate fraud, fall under this category. To authenticate Relying Party, apart from leveraging their OTCI, the identity apparatus 100 may be capable of providing an additional Natural Person Identity (NP ID). An example of a such an identity may be Public Key Infrastructure (PKI) based asymmetric keys and digital certificates securely stored in FIPS-certified chip. PKI may offer a significant advantage of offering digital signatures to achieve non-repudiation and legal tangibility. This NP ID verification may be available over "contact-based" and "contactless" interface. Every entity under Natural Person (NP) category may have the proposed identity apparatus 100, a device such as, a mobile phone or a standard computer to fetch CID or OTCI, and for mobile phone, the identity apparatus 100 may be linked to a mobile app and ideally a phone that supports Near Field Communication (NFC).

[0142] In some embodiment, for authentication process related to banking merchants, includes a banking customer may be making a card payment at the store till known as Card Present (CP) transaction or on the eCommerce website known as Card-Not-Present (CNP) transaction in order to purchase goods and services from a merchant, identifiable by Merchant ID.

[0143] In some embodiments, the authentication process for generic machine-to-machine authentication, which applies to all non-banking relying parties, for example travel agencies, insurance businesses, rental companies, phone providers, and so. As well as to internet of thing (IOT) devices like kiosks. To ascertain the identity of the relying party, strong verified identities will be leveraged. Examples of such identities include public or private trust certificates, such as Extended Validated (EV) Certificates, Legal Entity Identifiers (LEI), etc. Best in Breed FIPS / CCT1certified key protection techniques like HSMs and Trusted Platform Modules (TPM) will be mandated for all participating members.

[0144] Any entity wishing to obtain the OTCI will need to contact the identity provider (I DP) module 202 because the proposed identity apparatus 100 may not display the actual identity information. Following is an explanation of various examples of authentication flows. An ordinary PC or laptop browser can be used to carry out the process, and Application Programming Interface (API) can be used to automate it. Possible routes for automation in banking transactions include API integration with Verified by VISA, MasterCard SecureCode, RuPay Secure, and other systems. The Issuing Authority may support the various authorization policies.

[0145] In an embodiment of the present disclosure, the issuing authority may support the authorization policy for a natural person (self). It permits the end user to obtain the OTCI, authenticate with the identity provider (IDP) module 202, and finish the transaction at the relying party. This enables the end user to obtain their own identity number (OTCI) in the manner that is currently done. The authentication flow includes the end user launching the mobile app and pressing the power on / off button 108 of the identity interface 200, the PID (4838 2769 8348 ****), expiry date, and security code (if any) may be displayed on the first display unit 102, the second display unit 104, and the third display unit 106, end user touching the identity interface 200 on their mobile device, the mobile app reading the data from the identity interface 200 using near field communication (NFC), the mobile app then sending the information to the identity provider (IDP) module 202, in case of the NP(self) ID and PID matches, the identity provider (IDP) module 202 recognizes this as self-authentication, and the OTCI (4838276983488475) may be pushed by the identity provider (IDP) module 202 to the mobile app. The key advantage of such policy is that it is done now for online payments and other purposes, the end user might share their OTCI with other parties. The payment applications won't need to alter in any way, such as to accommodate 12-digit long card number. The disadvantage of such policy may be that an MITM attack could be launched against this strategy. Bypretending to be from a bank and inquiring about the functionality of the identity apparatus 100 and mobile app and so., the criminal obtains the OTCI, which may be the equivalent of a long card number, and proceeds with fraud against the gullible victim. Since this approach may be prone to traditional MITM, phishing etc. attacks, the OTCI validity should be short.

[0146] In an embodiment of the present disclosure, the issuing authority may support the authorization policy for a relying party natural person: It does not permit the end user to retrieve the OTCI; rather, the transaction must be completed by a broker, agent, or MITM attacker who must first authenticate with the identity provider (IDP) module 202. The identity provider (IDP) module 202 may provide a RP natural person with the identity apparatus 100, much like end users do. This may be especially beneficial for young and old persons, who may be more vulnerable to MITM attacks and more inclined to divulge card details. The authentication flow includes the end user pressing the button on the identity apparatus 100, the PID (4838 2769 8348 ****), the expiry date, and the security code (if applicable) may be displayed on the plurality of the display unit. The authentication flow further includes details being then sent to RP via phone or the internet. The authentication flow further includes RP then using a mobile device to tap the identity apparatus 100 and enter PID and any necessary identity holder details into the app. The authentication flow further includes the identity provider (IDP) module 202 capturing the RP (NP) ID. The authentication flow further includes the end user receiving a notification on the mobile app, and if they choose to share their OTCI, they approve. Eventually, the authentication flow further includes the identity provider (IDP) module 202 pushing the OTCI (4838 2769 8348 8475) to RP. OTCI may be mapped to RP (NP) ID and stored for forensics, audit, compliance, and dispute resolution. In the event that fraud may be reported using this unique OTCI, this particular RP is accountable. Since biometrics will be utilized for deduplication, RPs won't be able to fraudulently obtain a second identity. This will stop dishonest people from using false identities. OTCI will not be delivered if the end user taps the identity apparatus 100 on a mobile deviceto request it. The advantage of such policy strategy may be that with this strategy, card skimming, MITM attacks including phishing, vishing, smishing, pharming, fraudulent administrator and photo copy fraud will be eradicated. For legal tangibility, RP operations can also be digitally signed. The ID expiry recommendation may be that the expiry should be brief because the Stored OTCI (SOTCI) might be misused in offline mode. To elaborate, for example, in order to schedule a vacation, a victim gives passport information to a broker (Relying Party 1 - RP1 ). A fraudster uses this identity to apply for a bank loan after the identity information has been sold or compromised. Fraud may result if a Bank (Relying Party 2 - RP2) accepts this identity without using the identity provider (IDP) module 202 for validation - offline mode. This fraud situation should be addressed by having a brief expiration. RP2, however, can choose to appropriately verify the end user's identification with the identity provider (IDP) module 202.

[0147] In an embodiment of the present disclosure, the issuing authority may support the authorization policy for self and relying party natural person. It enforces both the Identity holder and broker / agent (or MITM attacker) to authenticate themselves to the identity provider (IDP) module 202, fetch the OTCI and complete the transaction. For critical operations where multiple entities may be involved and each one has to authorize in a random or specific sequence. The authentication flow includes end user pushing the power button on the identity apparatus 100, which displays PID (483827698348 ****) on the first display unit 102, Expiry and Security Code (if applicable). The authentication flow further includes end user loads mobile app and taps the identity apparatus 100 at mobile. The authentication flow further includes the mobile app gathering required details from the identity apparatus 100 via NFC and pushes the details to the identity provider (IDP) module 202. The authentication flow further includes matching NP (self) ID and PID and the identity provider (IDP) module 102 identifies this as self-auth. In contrast to another policies, the identity provider (IDP) module 102 now pushes the PID1 (4838 2769 8348 84**) to the mobile app which may be displayed subsequently. Theauthentication flow further includes end user giving PID1 to RP natural person. The authentication flow further includes RP natural person tapping the identity apparatus 100 on Mobile and punches PID1 at the App and requests OTCI of identity holder. The authentication flow further includes the identity provider (IDP) module 202 may be capturing RP NP ID. The authentication flow further includes end user receiving a notification on their Mobile App and should they decide to share their OTCI, will approve. The authentication flow further includes RP may be getting the OTCI (48382769 8348 8475). RP NP ID mapped to OTCI. The advantage of the policy may be that it permits the OTCI fetch procedure to involve several entities and prevents card skimming, MITM, phishing, vishing, smishing, fraudulent administrator and photo copy fraud. The ID expiry recommendation may be that the expiry should be brief because the Stored OTCI (SOTCI) might be misused at other RP in offline mode.

[0148] In an embodiment of the present disclosure, the issuing authority may support the authorization policy for relying party banking merchants. It prohibits any natural person from obtaining the OTCI; instead, the merchant application accepts the PID, authenticates to the identity provider (IDP) module 202, retrieves the OTCI, and completes the transaction. The identity holder needs to make an online / phone payment to merchant, the authentication flow may be detailed under FIG. 5E and 5F. The advantage of this strategy may be that it will eliminate card skimming, MITM, phishing, vishing, smishing, pharming etc. attacks. The ID expiry recommendation for this strategy may be that since the Merchant ID is mapped to OTCI, hence they may be the only ones allowed to use it, the expiry can be longer. This allows the identity data to be stored for longer period.

[0149] In an embodiment of the present disclosure, the issuing authority may support the authorization policy for relying party machine-to-machine: This holds true for all non-banking application scenarios, for example identity verification during mortgage or car rental or airline reservation, online service providers etc. Any natural person (end user, broker, agent, SO etc.) may not permitted by policy to retrieve the OTCI; instead, theRelying Party application accepts the PID, verifies identity with the identity provider (IDP) module 202, retrieves the OTCI, and completes the transaction. Those who own an identity must show, for example to government offices, internet service providers or airlines so they can save their passport information for future online check-ins, among other purposes. The authentication flow may be same as described in FIG. 3B. The advantage of this strategy may be that it will eliminate skimming, MITM, phishing, vishing, smishing, inside fraud, PH misuse, and so. The ID expiry recommendation may be that if the relying party is known to comply with local Data Protection Regulations, the expiry could be long. However, if the compliance is not assured, the expiry could be brief because the Stored OTCI (SOTCI) might be misused in offline mode.

[0150] In an embodiment of the present disclosure, the issuing authority may support the authorization policy for self, relying party natural person and machine-to-machine. For enforcing the end user, broker / agent (or MITM attacker) and relying party to authenticate themselves to the identity provider (IDP) module 202, retrieve the OTCI and completes the transaction. The authentication flow includes end user getting PID1 (4838 27698348 8***) from the identity provider (IDP) module 202 and passing on to broker / agent. The authentication flow further includes the broker / agent getting PID2 (4838 2769 8348 84**) from the identity provider (IDP) module 202 and passes to RP application. Broker / agent NP ID may be mapped to PID2. The authentication flow further includes the application finally getting OTCI (4838 2769 8348 8475) from the identity provider (IDP) module 202 and completes the transactions. RP application ID may be mapped to OTCI. The advantage may be that this strategy makes sure that PID1 , PID2, and OTCI may be mapped to the appropriate entities and that the broker or agent is not the victim of a phishing attempt. The ID expiry recommendation is that if the relying party is known to comply with local Data Protection Regulations, the expiry could be long. However, if the compliance may not be assured, the expiry could be brief because the Stored OTCI (SOTCI) might be misused in offline mode.

[0151] In an embodiment of the present disclosure, the issuing authority may support the authorization policy for identity holder consent. It requires the end user approval (for example through their mobile app push notification), as described in policies discussed above. If this policy is enabled, the identity holder has to approve OTCI / CID fetch by other entities. This may be comparable to end users authorizing transactions by mobile push notification for example mobile banking transaction etc.

[0152] In an embodiment of the present disclosure, the issuing authority may support the authorization policy for contact based or contactless transaction. At the time of the mobile app setup, this authorization may be saved in the mobile app and via NFC tap on a mobile app, contactless communication is possible. Other devices for example IOT, Kiosk, etc. may allow contact-based authentication; in such cases, the card must be inserted and a PIN may be needed, much like chip-and-pin payments at merchant tills. The authentication flow may be dependent on the Issuing Authority Authentication Authorisation Policies (I3AP) policy, the device (mobile phone or others) will display the message to tap or insert the identity apparatus 100. The advantage of this policy may be that it will allow different level of authentications depending on the use case, device types and level of security required.

[0153] In an embodiment of the present disclosure, the issuing authority may support the authorization policy for mobile app authentication mode - PIN or biometric based. This authorization may be stored in the mobile App at time of the mobile app setup. To access the IDP mobile app when it may be launched, it will allow either PIN or biometrics - finger print or facial recognition as supported by the Mobile device. The authentication flow may be that upon launching the app, the user will be asked to enter a PIN or utilize biometrics to unlock it. The advantage of this policy may be that depending on the use case and desired level of security, this policy will permit varying levels of authentication.

[0154] In an embodiment of the present disclosure, the issuing authoritymay support the authorization policy for online or offline mode of authentication. The system 200 will offer online and offline authentication methods. In the offline mode, the end user shares the RID, expiry, and security code (if applicable) with the RP. The RP then uses this information to retrieve the OTCI / CID whenever it may be online. The identity apparatus 100 may be powered by a battery, and if not charged, the plurality of display unit will not show the PID. In that scenario, the SO may still be able to obtain the printed account number and, upon proper I3AP authorization, obtain the OTCI / CID at a later time, which may be "back-in-time" identification. The advantage of this policy may be that security personnel can track individuals using offline mode even if the identity apparatus 100 may not be charged or they may not be in an area with internet access, or the internet has been shut down. This may be comparable to the current system of identifying people with ordinary ID cards. Through this policy, Issuing Authorities and Governments allow certain law enforcement agencies to fetch OTCI / CID (and other details) with just printed account number on the identity apparatus 100 - no PID or expiry required. This may be a special power granted to select security officers nominated by concerned agencies. SOs will have to authenticate themselves to I DP to fetch these details. The disadvantage may be that the financial transactions will not be supported by the offline authentication mechanism. Also, CNP payments must be made with the identity apparatus 100 that have been charged.

[0155] In an embodiment of the present disclosure, the issuing authority may support the authorization policy for PID and expiry date synchronization: For an instance, in a 5 minutes time interval, the end user may generate the PID and security code (optional) just before a time internal finishes (T = 0), and these values may reach the identity provider (IDP) module 202 in the subsequent time interval (T = 5 minutes). The identity provider (IDP) module 202 will compute these values for pre-configured "previous" time intervals in such a case. For example, there may be two or three permitted time slots, or ten to fifteen minutes. The identity provider (IDP) module 202 can also be set up to compute 'n' time intervals ahead oftime

[0156] In an embodiment of the present disclosure, the issuing authority may support the authorization policy for OTPI time interval. The time interval after which the identity number (OTPI) will change may be up to the issuing authority to determine. However, after the identity apparatus 100 has been issued, this value cannot be modified because it may be hardcoded into the identity apparatus 100.

[0157] In an embodiment of the present disclosure, the issuing authority may support the authorization policy for incorrect PIN attempts. This policy can limit the total number of permitted PIN tries, after which the account may be temporarily locked, in order to resist brute-force attacks.

[0158] Except for I3AP policy for OTPI Time Interval, issuing authorities can configure all other policies in real-time depending on risk assessment.

[0159] In an alternate embodiment, the I3AP policies define the duration of an identity’s validity. The policies for natural person (self), relying party natural person, and self & relying party natural person recommends shortlived ID. The validity under merchant policy ought to be extended. Nonetheless, the expiry may be brief or prolonged with other scenarios. Therefore, if the issuing authority expects a range of user scenarios, hardcoding the identity validity at the time of issuance will be challenging. An entirely new approach to solving this issue might be to provide the relying party with dynamic OTCI expiry dates. This method eliminates the need for an expiry date displayed on the second display unit 104 on the identity apparatus 100.

[0160] In an alternate embodiment, the identity apparatus 100 may have no display unit. The end user may use NFC to tap the identity apparatus 100 on their phone, and IDP pushes the OTCI, security code, and expiry dates to the mobile app. Security personnel might still utilize printed account numbers and back-in-time identification to verify users offline. The advantage of this approach may be that it will help lower the cost of theidentity apparatus 100 and no dependence on charging. The disadvantage is that for card-not-Present transactions, this strategy may not be practical for users using a laptop or PC browser. For mobile users; it will be challenging if the mobile device is lost or stolen; or users using a feature phone.

[0161] In an alternate embodiment, the identity apparatus 100 may be solely software-based. The shared secrets of the end user may be stored and secured on their mobile device; no hardware associated with the identity apparatus 100 will be distributed. The user will use the smartphone app in place of a real NFC tap. The advantage of this approach may be that it is very economical, rapid provisioning, no need for logistics, and no need for the identity apparatus 100 charging. The disadvantage may be lack of FIPS- certified key storage makes it vulnerable to malware like Pegasus, which infected both iOS and Android phones, unsuitable for use cases involving national ID cards, voter ID cards, passports, and driver's licenses, among others, cannot work in offline mode, and for Card-Not-Present transactions using a laptop or PC browser, this method may not be feasible. Due to reliance on mobile phones, it will be difficult if they may be lost, stolen, or used by someone with a feature phone.

[0162] In an alternate embodiment, the identity apparatus 100 may be enabled with a SIM or eSIM card so that, in accordance with I3AP policies, the OTCI / CID and / or expiry date can be pushed straight to the identity apparatus 100 and shown on the plurality of display unit screen at the touch of a button. The advantage of this approach may be that it eliminates the need of a mobile phone, desktop browser to fetch OTCI / CID. The disadvantage may be presence of SIM might raise privacy concerns and international travelers may face data plan roaming issues.

[0163] Fig. 5A illustrates a block diagram for an exemplary proposed identity apparatus 200 with 18 Digit PAN number and three blocks, according to an embodiment of the present invention.

[0164] In an embodiment of the present disclosure, the One-Time PartialIdentity (OTPI) provides an effective way for the issuing authority to do away with PID caching. Referring to FIG. 2E, providing an exemplary embodiment of eighteen-digit identity number. The identity apparatus 100 may include one extra logical block, B3, rather than two blocks B1 and B2. The time intervals are, as an example, B1 (1 year), B2 (5 minutes), and B3 (5 minutes). By design, B1 and B2 values may always be shown when the end user pushes the button, while B3 may be obfuscated. The process for authentication and OTCI retrieval from the the identity provider (IDP) module 202 may be as follows:T=0 min, PID = 5849 3979 6061 278 ** 4 & OTCI returned = 5849 3979 6061 278 55 4T=5 min, PID = 5849 3979 6061 202 ** 4 & OTCI returned = 5849 3979 6061 278 37 4T=10 min, PID = 5849 3979 6061 203 ** 4 & OTCI returned = 5849 3979 6061 278 64 4

[0165] The term One Time Partial Identity (OTPI) comes from the fact that the PID shown may be dynamic, time-bound, partial and only produced once. The main benefit of OTPI may be that it provides a dynamic partial identity, making it impossible for anyone — even malicious actors to cache them.

[0166] FIG. 5B illustrates a block diagram for an exemplary PID and OTCI Transaction at T = 365 Days (beginning of 2ndyear), according to an embodiment of the present invention.

[0167] In an embodiment of the present disclosure, the first logical block (B1 ) may have validity for one year. Thus, at T = 365+ days, or the start of the second year, the B1 digits will also alter and stay that way until the end of the second year. This may be an additional time interval that the issuing authority could determine based on their security posture. As in 1styear, during the entire 2nd year, the last 4 digits will change every 5 minutes.

[0168] FIG. 5C illustrates a block diagram for an exemplary prevention of a bad actor from fetching Complete Identity, according to an embodiment of the present invention.

[0169] For an instance, a fraudster targeting a victim and attempting to steal identity information for example card number, expiry date, security code and so. This assault may be initiated by any medium for example SMS, email, web, phones, and so. The unsuspecting victim ends up giving the attacker the Partial Identity Number, security code and expiry date. The scammer requires the Complete identity in order to use the card fraudulently. With traditional ID cards, it would be game over by now. But the complete card number may be just not dis played by this apparatus. Thus, the adversary contacts the identity provider (IDP) module 202 and needs to authenticate. This verification puts up a barrier. Because the fraudster wouldn't have the necessary credentials, their attempt to steal identity data or money would be fruitless.

[0170] In a preferred embodiment, the system 200 provides defense against a range of other threats, such as malware-based MITB, phishing, vishing, smishing, and pharming. Additionally, this guards against photocopy fraud. Since the OTCI will be linked to the identity number of the requesting entity, in the event of inside fraud, the identity provider (IDP) module 202 may revoke this identity number as soon as the fraud may be reported and thus, guaranteeing that future fraud may be avoided by same fraudster.

[0171] FIG. 5D illustrates a block diagram for an exemplary relying party obtains the OTCI and account number in a banking payment transaction, according to an embodiment of the present invention.

[0172] In an alternative embodiment, the identity apparatus 100 may display the OTCI upfront and renew it. For an instance, every 5 minutes - One Time Identity (OTI). However, bad actors can consume this identity straight away without authenticating with the identity provider (IDP) module 202. During the 5-minute time window, multiple attack vectors would be possible such as MITM. An analogy here may be Dynamic Security Code offered by EMVcards. This fraud opportunity may be eliminated with Partial ID (PID) or One Time Partial Identity (OTPI).

[0173] FIG. 5E illustrates a block diagram for an exemplary PID and OTCI Banking (Payment) Transaction, according to an embodiment of the present invention.

[0174] Since financial fraud may be perhaps the most serious threat. For an instance, the authentication flow using a bank card transaction includes the end user must supply their PID, card expiry date, and security code, in order to purchase products or services from a merchant. The authentication flow includes the merchant being directed to the Acquiring bank - this is Merchant’s bank. Apart from PID, Card Expiry and Security code, this step requires Merchant ID. At this stage, the bank validates the merchant leveraging current authentications techniques. The authentication flow includes acquiring Bank forwards card details to Card Scheme. The authentication flow includes routing the Card Association transaction to the Issuer bank once it has determined which bank may be the Issuer (the bank of the end user). The authentication flow includes the issuer bank authenticating itself to the identity provider (IDP) module 202 and passes on the details. The authentication flow includes the issuer bank receiving the complete identity (bank card number) following successful authentication. To stop replay attacks, Merchant ID and Acquiring Bank's ID may be linked to OTCI. The procedure for obtaining Merchant ID differs depending on the card scheme; for instance, Mastercard provides Merchant Identifier, RuPay offers Partner ID and so. The intention may be to prevent any other merchant from using or abusing this unique OTCI. The authentication flow includes issuer bank confirming end user has sufficient funds. The authentication flow includes card association settling the payment with acquiring bank. The authentication flow includes merchant getting the payment acknowledgment. For refunds, OTCIs will be mapped to transaction identifiers; for example, RuPay leverages Transaction ID.

[0175] In an embodiment of the present disclosure, during the Card Present(CP) Transaction despite the first display unit 102 may only be displaying a portion of the ID, the identity apparatus 100 actually possesses the complete identity, which it will use to process contactless or Chip & PIN payments at the sales counter.

[0176] FIG. 5F illustrates a block diagram for an alternative exemplary approach of OTPI and OTCI Banking (Payment) Transaction, according to an embodiment of the present invention.

[0177] In an alternative embodiment, with a different flow in which the merchant gets the OTCI straight from the identity provider (IDP) module 202 and continues the pre-determined operations. The benefits of this implementation include the identity provider (IDP) module 202 may be having direct visibility of the merchant, it could authenticate it more effectively and mapping Merchant ID with OTCI and the acquiring, issuing and bank card scheme may process 16-digit Card numbers as usual and not deal with 12-digit card numbers.

[0178] FIG. 5G illustrates a block diagram for an exemplary partial identity mapping with end user account number, according to an embodiment of the present invention.

[0179] In an embodiment of the present disclosure, the identity provider (IDP) module 202 may be linked to an identity provider (IDP) server and an IDP mobile app. By design, B1 remains static for a relatively longer period of time, for example, 1 year. Shared Secret 1 (SS1 ) corresponds to B1 , and both the identity apparatus 100 and the IDP server may hold this key. When the user generates OTPI / PID, the B1 component in identity number is good enough to identify the user. When the card is provisioned, B1 =698348, and this corresponds to Account No. =123456. At beginning of 2nd year, time interval in the identity apparatus 100 and IDP server will trigger change of B1 , which is now 000511 and both parties will have this value, and thus the identity provider (IDP) module 202 will automatically map this to the Account number 123456. The process continues each year.

[0180] FIG. 5H illustrates a block diagram for an exemplary stored OTCI (SOTCI) validation transaction, according to an embodiment of the present invention.

[0181] A use case in which the Issuing Authority, bank in this example, allows for longer validity of identity number and the end user chooses to save the OTCI with the relying party — in this example, the merchant for an extended duration. Other examples include internet shopping portals, parking or movie apps, and so. The authentication flow includes the user making a purchase, merchant leverages stored OTCI, acquiring bank passes the card data to bank card scheme, data reaches issuer bank and then lastly this data is fed to the identity provider (IDP) module 202. Since OTCI is mapped to Merchant ID, IDP will verify whether this OTCI is being used at the same (approved) merchant. The transaction is permitted if the match is successful, indicating that the same authorized merchant is using the OTCI. Match failure indicates that the original merchant's stored OTCI has been compromised and is being attempted to be used by a malicious party. The transaction is declined, and the merchant is notified. Depending on the outcome, Issuer bank communicates Balance OK / Not OK. Depending on the outcome, if transaction is successful, the card scheme communicates payment settlement message to acquiring bank. Depending on the outcome of previous three steps, acquiring bank sends successful or failed message to the merchant.

[0182] Potential causes of SOTCI fraud embody situations where a victim pays by phone for a CNP transaction and a rogue employee at the merchant steals the card information by writing it down or breach of the merchant database (non-compliance with PCI-DSS) that result in the disclosure of SOTCI information. In the event that an unrelated attack compromises the merchant, the system will prevent the card from being misused at a different merchant location. In order to obtain a distinct OTCI to RP mapping (1 :1 ), the IDP server has the ability to prevent the end user from reauthenticating within a 5-minute timeframe.

[0183] The system 200 and method 300 can be applied to 2FA online transactions for example Net Banking use cases among others. The following mechanisms may be available for use. In an embodiment of the present disclosure, the PID displayed on the identity apparatus 100 can act as Username. This way, the users will not have to remember their username. Since OTPI are dynamic, it may be used to produce "dynamic usernames," an additional security layer that will deter fraudsters. This can be termed as One Time User Name (OTUN). The security code of the identity apparatus 100 serves as a dynamic password. The mobile push notification and approval via mobile app is also available.

[0184] The system 200 and method 300 of the renewable identities using One Time Partial Identity (OTPI) & One Time Complete Identity (OTCI) offer various advantages. It offers a next generation robust technique to secure identities by offering dynamic Personally Identifiable Information (DPI I). The system 200 and method 300 provide a broad-spectrum technique that may be used with a variety of Real-World physical ID systems such as passports, Bank cards, National ID cards etc. and online identities such as Usernames.

[0185] Further, in order to accommodate different needs and the security posture of the issuing authority, the system 200 allows a range of combinations between One Time Identity (OTI), Partial Identity (PID), One Time Partial Identity (OTPI), Complete Identity (CID) and One Time Complete Identity (OTCI).

[0186] The numerous I3AP policies available in the system 200, and they can be configured almost instantly to meet the evolving security needs of the issuing authorities. The system 200 and method 300 may completely eliminates card skimming fraud. The system 200 and method 300 may have ability of OTPI and PID to successfully assist in defending against phishing, vishing, smising, MITB, pharming, and other forms of attacks that target personally identifiable information (PH) during contactless or card-not- present transactions is by far its greatest advantage.

[0187] Another advantage is that issuing authorities can significantly reducelogistical costs since there will be no need to reissue and ship cards because of their expiration. Each of these end-user OTCIs may be linked to relying party. Stated differently, as a particular OTCI may only be utilized by a single, distinct relying party. Its greatest benefit is the ability to cope with PH misuse efficiently. Additionally, this method 300 guards effectively against insider fraud.

[0188] Since all identity fields — ID number, expiry date, and security code — are available as they should be on traditional ID cards, this technique guarantees that there will be no impact on the ecosystem applications that expect these fields and consume the data. Since the hackers won't be able to do anything using Partial ID, there is no need for end-user education or awareness campaigns warning users not to share card data or other personal information.

[0189] The system 200 is not invasive and does not drastically alter users' conduct. Users will go through the same process as they may be used to, which includes receiving notifications via mobile push and approving CNP transactions. During hotel check-in, passports and driver's licenses may be scanned; this approach and technology will help avoid photocopy fraud.

[0190] Regarding strong two factor authentication, apart from dynamic passwords, this technique also offers dynamic usernames - One Time Username (OTUN). With the hardware identity apparatus 100, the system and method will be able to offer three-factor authentication

[0191] Through Identity Federation, Identity issued by one issuing authority can be used by other relying parties for two-factor authentication. This can be an additional source of revenue for issuing authorities. Users will be able to roam across and authenticate securely on a variety of devices, such as personal digital assistants, kiosks, and home and office PCs. Secure crypto key storage backed by a hardware the identity apparatus 100 will fend off malware attacks like Pegasus and so.

[0192] In a nutshell, the end user only has partial identity. All relying parties(and potential attackers) who need to consume the identity, may be required to authenticate to the identity provider to fetch the Complete Identity. This technique completely eliminates static identities and prevent various threats. The table 1 provides identified threats and mitigation offered by the system 200 and the method 300.Table 1 : Identified Threats and Mitigation

[0193] While the invention has been described in connection with what is presently considered to be the most practical and various embodiments, it is to be understood that the invention is not to be limited to the disclosed embodiments, but on the contrary, is intended to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims.

[0194] This written description uses examples to disclose the invention, including the best mode, and also to enable any person skilled in the art to practice the invention, including making and using any devices or systems and performing any incorporated methods. The patentable scope the invention is defined in the claims, and may include other examples that occur to those skilled in the art. Such other examples are intended to be within the scope of the claims if they have structural elements that do not differ from the literal language of the claims, or if they include equivalent structural elements within substantial differences from the literal languages of the claims.

Claims

CLAIMSI / We Claim:

1. An identity apparatus (100) with dynamic personally identifiable information (DPI I) feature, the identity apparatus (100) comprising: a first display unit (102) on the identity apparatus (100), the first display unit (102) configured to display an identity number including, a one-time partial identity (OTPI) or a partial identity (PID); a second display unit (104) on the identity apparatus (100), the second display unit (104) configured to display dynamic expiry date of the one-time complete identity (OTCI); a third display unit (106) on the identity apparatus (100) the third display unit (106) configured to display a dynamic security code; a power on / off button (108) installed on the identity apparatus (100), the power on / off button (108) having the operability characterized by: keeping the first display unit (102), the second display unit (104) and the third display unit (106) switched off and blank in a ‘power off’ state; and activating the first display unit (102), the second display unit (104) and the third display unit (106) in a ‘power on’ state; an integrated circuit chip (110) installed on the surface of the identity apparatus (100), the integrated circuit chip (110) configured to store identity related sensitive data such as shared secret keys; and a plurality of identifier (114) etched or printed on the identity apparatus (100), the identifiers (114) include, a name, a photograph, a signature, name of the issuer, and account number.A computer-implemented system (200) of generating renewable, dynamic and secure identities, the system (200) comprising: an identity provider (IDP) module (202) configured to: generate a new identity number, an expiry date, and a security code after a predetermined threshold time interval; manage user identities and authentication; and decide the expiry date of each unique one-time complete identity (OTCI) that is different for a plurality of end user, wherein the end user has several one-time complete identities (OTCI) in the identity provider module (202); a backend infrastructure (204) operationally coupled to the identity provider (IDP) module (202), the backend infrastructure (204) configured to support the operation of the identity provider (IDP) module (202); a database (206) operationally coupled to the backend infrastructure (204), the database (206) configured to securely store user credential related information such as shared secret keys, configuration settings, and generated identity logs; a security key generator (208) operationally coupled to the identity provider (IDP) module (202), the security key generator (208) configured to generate: a first shared secret key (SS1); a second shared secret key (SS2); and a third shared secret key (SS3); a communication protocol module (210) linked to the identity provider (IDP) module (202), the communication protocol module (210)configured to establish communication between the identity provider (IDP) module (202); an end user interface (212) operationally coupled to the communication protocol module (210), the end user interface (212) configured to generate and display a one-time partial identity (OTPI). wherein the new identity number as generated by the identity provider (IDP) module (202) and the end user interface (212) is divided into at least two logical blocks further having a first logical block (B1 ) and a second logical block (B2) and the security code generated by end user interface (212) is a third logical block (B3), wherein the values of the second logical block (B2) and the third logical block (B3) changes simultaneously due to synchronization of time intervals, wherein the partial identity information displayed on the end user interface (212) as a partial identity (PID), wherein the partial identity information displayed on the end user interface (212) is dynamic and time bound; a validation module (214) operationally coupled to the end user interface (212), and the identity provider (IDP) module (202), the validation module (214) configured for: comparing the security code received from the relying party interface (216) and matches the one that identity provider (IDP) calculated by the identity provider (IDP) module (202); and successful validation if the incoming security code matches the one that identity provider (IDP) module (202) has calculated;a relying party (216) operationally coupled to the communication protocol module (210) and the validation module (214), the relying party interface (216) configured to: receive a one-time complete identity (OTCI) generated by the identity provider (IDP) module; and authenticate the end user to the identity provider module (202) server, wherein the complete end user authentication transaction requires one-time complete identity (OTCI) information from Identity Provider module (202) server, wherein the identity provider module (202) delivers the one-time complete identity (OTCI) and expiry date to the end user or relying party (216) or both.

3. The system (200) as claimed in claim 2, wherein the identity provider (IDP) module (202) generates the new identity number in form a one-time complete identity (OTCI) value based on a time interval and a shared secret key as generated by the security key generator (208).

4. The system (200) as claimed in claim 2, wherein the end user interface (212) is further linked to a mobile application to facilitate user authentication.

5. The system (200) as claimed in claim 2, wherein the frequency at which the identity information displayed on the end user interface (212) changes, vary from one second to several years.

6. The system (200) as claimed in claim 5, wherein the some or all of the identity information displayed on the end user interface (212) produces unique and non-repeatable one time partial identity (OTPI) after a defined time interval.A method (300) for generating renewable, dynamic and secure identities, the method (300) comprising: turning ‘on’ a power on / off button (108) on an identity apparatus (100) or an end user interface (212) and displaying a partial identity (PID) or a one-time partial identity (OTPI), an expiry date, and a security code respectively on a first display unit (102), a second display unit (104), and a third display unit (106); sending the partial identity (PID) or a one-time partial identity (OTPI), the expiry date, and the security code displayed to a relying party (216), which in turn, communicates with identity provider (IDP) module (202) for authentication and obtaining a one-time complete identity (OTCI), wherein the identity provider module (202) may deliver a part of one-time complete identity (OTCI) to relying party (216); using a first logical block (B1 ) for identifying the user by the identity provider (IDP) module (202); computing and validating a third logical block (B3) based on the received security code using a third shared secret key (SS3); verifying the incoming expiry date via a validation module (214) and if it matches with logic of the identity provider (IDP) module (202) expiry date, the validation is successful; computing a second logical block (B2) based on the received onetime partial identity (OTPI) using a second shared secret key (SS2) after successful validation, the second logical block (B2) is computed at the identity provider (IDP) module (202) using a predetermined protocol and a time interval synchronized with the identity apparatus (100);appending the second logical block (B2) to the received one-time partial identity (OTPI) to generate a one-time complete identity (OTCI); and returning the generated one-time complete identity (OTCI) via the identity provider (IDP) module (202) to relying party to complete an enduser transaction, wherein the identity provider (IDP) module (202) and identity apparatus 100 maintains time counter for measuring or counting time, wherein the identity provider (IDP) module (202) and identity apparatus 100 maintain same set of shared secret keys and time counter leveraged by producing Identity information.

8. The method (300) as claimed in claim 7, wherein the mapping of unique one-time complete identity (OTCI) to relying parties further comprises: allotting every one of the relying parties (216) a relying party identity (RPI) that is a unique identity; mapping each one-time complete identity (OTCI) against relying party identity (RPI) by the identity provider module (202) to track misuse of identities; and storing one-time complete identity (OTCI) as stored one time complete identity (SOTCI) by the relying party (216).

9. The method (300) as claimed in claim 8, wherein the relying party (216) leveraging stored one time complete identity (SOTCI) for executing a transaction and the identity provider module (202) validating the usage further comprises: mapping the unique stored one time complete identity (SOTCI) with the relying party identity (RPI) by the identity provider module (202);checking if the stored one time complete identity (SOTCI) with the relying party identity (RPI) and allowing transaction if a match occurs; and declining transaction if the stored one time complete identity (SOTCI) mismatches with the relying party identity (RPI) and preventing potential fraud.

10. A method (300) according to claim 1, wherein the method (300) also provides dynamic end user authentication including: obtaining a dynamic username by the one time partial identity (OTPI) from the end user interface (212) as a one time username (OTUN); and using the security code (B3) as a dynamic password.

Citation Information

Patent Citations

  • System for biometric security using a smartcard

    US20080011830A1

  • Applying a partial password in a multi-factor authentication scheme

    US20140101738A1