Anonymous Authentication via Low Energy Wireless Token

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods are vulnerable to attacks, as they often rely on weak or easily compromised user credentials, and there is a lack of effective mechanisms to securely manage and verify user identities across multiple enterprises, leading to potential identity theft and compromised security.

Innovation Solution

An authentication system that utilizes low energy wireless devices, such as NFC-enabled devices, in conjunction with user devices to securely authenticate users by aggregating and anonymizing credentials, creating multiple secure connections between user devices, authentication services, and enterprises, ensuring that credentials are not tied to specific identities, thus enhancing security and privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication methods (passwords, OTPs, smartcards) are used, then authentication can be performed, but the system is vulnerable to attacks such as MITM and MITB

Engineering Contradiction:
Improveauthentication securityVSAvoidsusceptibility to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an authentication service as an intermediary between the user device and the enterprise. This service receives credentials from the user device, verifies them against stored credentials, and returns authentication results. The intermediary architecture prevents direct exposure of credentials to enterprises, reducing vulnerability to MITM and MITB attacks while maintaining reliable authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple digital identities are maintained across different enterprises, then each enterprise can verify user identity, but the risk of identity theft and compromise increases

Engineering Contradiction:
Improveidentity verificationVSAvoididentity theft risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the credential storage and management function from individual enterprises and centralizes it in an authentication service. User credentials are stored anonymously in the authentication service rather than being distributed across multiple enterprises. This extraction reduces the attack surface for identity theft while maintaining the ability of enterprises to verify user identities through the authenticated session information.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If user credentials are shared across multiple enterprises, then authentication is simplified, but a single compromise allows access to all accounts

Engineering Contradiction:
Improveauthentication convenienceVSAvoidaccount security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a universal authentication service that handles authentication for multiple enterprises through a single interface. The user device establishes one authenticated session with the authentication service, which then serves as proof of identity across all participating enterprises. This multi-functional approach provides authentication convenience while maintaining security, as compromising one enterprise does not expose credentials for other enterprises.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If additional credentials (social security number, personal information) are required for financial institutions, then identity verification is strengthened, but the complexity of credential management increases

Engineering Contradiction:
Improveidentity verification strengthVSAvoidcredential management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple credential types (passwords, biometrics, possession-based credentials) into a single authenticated session managed by the authentication service. Instead of requiring users to manage separate credentials for each enterprise, the system combines verification of multiple factors into one unified authentication process. This reduces credential management complexity while maintaining strong identity verification through the use of multiple authenticators.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12022282B2Anonymous authentication and remote wireless token access
Publication Date: 2024.06.25 PROVE IDENTITY INC
  • US12022282B2 patent drawing
  • US12022282B2 patent drawing
  • US12022282B2 patent drawing

AI summary

Provided is a method for operating an authentication server for authenticating a user who is communicating with an enterprise via a network. The method include receiving, via the network, a first authenticator including first information from a low energy wireless device received via a user device wirelessly, and storing the first authenticator. When the authentication service later receives, from the enterprise, a request to authenticate the user, the authentication server transmits an authentication request to the user device via the network requesting that the user read information from the low energy wireless device using the user device. The information received from the low energy wireless device in response to the authentication request is then used authenticate the user by comparing the information received from the low energy wireless device due to the authentication request with the stored first authenticator.