Anonymized User Feature Authentication Through a Trusted Authority
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods require users to reveal sensitive personal data directly to querying systems, posing risks of data breaches and compromising user privacy.
Innovation Solution
A method and device for authenticating user features using a protected central authority that generates and provides anonymized authentication information, allowing confirmation to querying systems without revealing actual personal data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users reveal sensitive personal data directly to querying systems for authentication, then authentication can be performed, but security risks increase and user privacy is compromised
Solution Approach 1:
The patent introduces a trusted authority as an intermediary between the user and the querying system. The user authenticates with the trusted authority which then provides anonymized authentication information to the querying system. This mediator approach allows authentication to occur without the user's sensitive personal data being exposed to the querying system, thus maintaining authentication reliability while eliminating data breach risks.
Solution Approach 2:
The patent extracts the sensitive personal data from the authentication process that reaches the querying system. Only anonymized authentication information is transmitted to the querying system, while the complete personal data remains securely stored with the trusted authority. This extraction approach maintains authentication functionality while removing the harmful exposure of sensitive data.
2Reliability
If querying systems store personal data for authorization proof, then authorization can be verified, but security risks and operational complexity increase
Solution Approach 1:
The trusted authority acts as an intermediary that handles the storage and management of personal data, freeing the querying system from this burden. The querying system only needs to verify anonymized authentication information provided by the trusted authority, simplifying its operational complexity while maintaining reliable authorization verification.
Solution Approach 2:
Instead of storing actual personal data, the system uses copies in the form of anonymized authentication information. These anonymized tokens contain the necessary verification capability without replicating the sensitive personal data, thus enabling authorization proof while reducing security risks and operational complexity.
3Ease of operation
If users disclose personal data to third parties for authentication, then access to services is granted, but user security concerns increase
Solution Approach 1:
The trusted authority serves as a mediator that users interact with once to establish authentication. After this initial interaction, users can access services using anonymized information without repeatedly disclosing personal data to multiple third parties. This maintains ease of service access while dramatically reducing user security risks.
Solution Approach 2:
The authentication with the trusted authority is performed in advance, before the user needs to access various services. This preliminary action establishes the user's credentials, and subsequent service accesses use anonymized tokens without requiring further personal data disclosure. This approach maintains convenient service access while minimizing security risks.
Data Source
AI summary
The present invention relates to the anonymized confirmation of personal user features. A user authenticates the user features to be checked with a separate authentication device. The authentication with a service provider takes place by way of anonymized authentication information.
