Anonymous Authentication via Low Energy Wireless Token
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods are vulnerable to attacks, as they often rely on weak or easily compromised user credentials, and there is a lack of effective mechanisms to securely manage and verify user identities across multiple enterprises, leading to potential identity theft and compromised security.
Innovation Solution
An authentication system that utilizes low energy wireless devices, such as NFC-enabled devices, in conjunction with user devices to securely authenticate users by aggregating and anonymizing credentials, creating multiple secure connections between user devices, authentication services, and enterprises, ensuring that credentials are not tied to specific identities, thus enhancing security and privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authentication methods (passwords, OTPs, smartcards) are used, then authentication can be performed, but the system is vulnerable to attacks such as MITM and MITB
Solution Approach 1:
The patent introduces an authentication service as an intermediary between the user device and the enterprise. This service receives credentials from the user device, verifies them against stored credentials, and returns authentication results. The intermediary architecture prevents direct exposure of credentials to enterprises, reducing vulnerability to MITM and MITB attacks while maintaining reliable authentication.
2Reliability
If multiple digital identities are maintained across different enterprises, then each enterprise can verify user identity, but the risk of identity theft and compromise increases
Solution Approach 1:
The patent extracts the credential storage and management function from individual enterprises and centralizes it in an authentication service. User credentials are stored anonymously in the authentication service rather than being distributed across multiple enterprises. This extraction reduces the attack surface for identity theft while maintaining the ability of enterprises to verify user identities through the authenticated session information.
3Ease of operation
If user credentials are shared across multiple enterprises, then authentication is simplified, but a single compromise allows access to all accounts
Solution Approach 1:
The patent implements a universal authentication service that handles authentication for multiple enterprises through a single interface. The user device establishes one authenticated session with the authentication service, which then serves as proof of identity across all participating enterprises. This multi-functional approach provides authentication convenience while maintaining security, as compromising one enterprise does not expose credentials for other enterprises.
4Reliability
If additional credentials (social security number, personal information) are required for financial institutions, then identity verification is strengthened, but the complexity of credential management increases
Solution Approach 1:
The patent merges multiple credential types (passwords, biometrics, possession-based credentials) into a single authenticated session managed by the authentication service. Instead of requiring users to manage separate credentials for each enterprise, the system combines verification of multiple factors into one unified authentication process. This reduces credential management complexity while maintaining strong identity verification through the use of multiple authenticators.
Data Source
AI summary
Provided is a method for operating an authentication server for authenticating a user who is communicating with an enterprise via a network. The method include receiving, via the network, a first authenticator including first information from a low energy wireless device received via a user device wirelessly, and storing the first authenticator. When the authentication service later receives, from the enterprise, a request to authenticate the user, the authentication server transmits an authentication request to the user device via the network requesting that the user read information from the low energy wireless device using the user device. The information received from the low energy wireless device in response to the authentication request is then used authenticate the user by comparing the information received from the low energy wireless device due to the authentication request with the stored first authenticator.


