Anonymous Device Fingerprinting via Cryptographic Proof

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device registration approaches are vulnerable to spoofing attacks, as metadata such as IP addresses, MAC addresses, and user agent strings can be easily manipulated by attackers, allowing them to bypass authentication mechanisms.

Innovation Solution

The use of a user-agent-based non-extractable keypair to generate a cryptographic proof that uniquely identifies a device, ensuring that the device's fingerprint is generated and verified in an isolated and secured environment, thus eliminating the risk of spoofing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If device registration is performed using metadata such as IP address, MAC address, and user agent string, then device identification can be implemented, but the system becomes vulnerable to spoofing attacks since all these data points can be manipulated by attackers

Engineering Contradiction:
Improvedevice registrationVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces traditional metadata-based device identification (mechanical/system-level data collection) with cryptographic proof-based identification. Instead of relying on manipulatable metadata like IP addresses and user agent strings, the system uses cryptographic proofs generated by the device's secure environment to uniquely identify the device. This substitution eliminates the spoofing vulnerability inherent in metadata-based approaches while maintaining ease of device registration.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces cryptographic proofs as an intermediary mechanism between the device and the authentication system. These proofs serve as a trusted mediator that verifies device identity without exposing vulnerable metadata. The cryptographic proof acts as a secure bridge that allows the system to identify devices reliably without directly relying on manipulatable data points like IP addresses or user agent strings.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If synchronous authentication mechanisms are used to eliminate user-known passwords, then the shelf-life of stolen credentials is limited, but users can still be tricked into entering authentication data into illegitimate sites

Engineering Contradiction:
Improvecredential securityVSAvoidphishing attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary device identification and verification before authentication credentials are exchanged. By establishing device identity through cryptographic proofs in advance, the system creates a trusted foundation that prevents phishing attacks. The device is registered and verified before any authentication data is shared, ensuring that even if users are tricked into illegitimate sites, the cryptographic binding prevents credential theft from being useful.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent inverts the traditional authentication model by prioritizing device identification over credential verification. Instead of trusting credentials and verifying devices, the system first establishes device identity through cryptographic proofs and then uses that trusted device identity to secure credential exchange. This inversion ensures that even stolen credentials cannot be used without the corresponding cryptographic proof, effectively neutralizing phishing attacks.

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If cryptographic proofs are used for device identification, then spoofing resistance is achieved, but the system complexity increases due to the need for isolated and secured environments for keypair generation

Engineering Contradiction:
Improvespoofing resistanceVSAvoidsecure environment requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service device identification by leveraging the device's own secure environment (such as hardware security modules or trusted execution environments) to generate and store cryptographic keypairs. The device serves itself by using its built-in secure capabilities to create cryptographic proofs without requiring external verification infrastructure. This self-service approach achieves spoofing resistance while minimizing system complexity, as each device independently provides its own security functionality.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250112917A1Anonymous device fingerprinting for device verification
Publication Date: 2025.04.03 PAYWARD INC
  • US20250112917A1 patent drawing
  • US20250112917A1 patent drawing
  • US20250112917A1 patent drawing

AI summary

Systems, methods, and computer readable media are described herein that use a user-agent-based non-extractable cryptographic keypair to generate a cryptographic proof containing a device fingerprint that an authentication system can use to subsequently identify and/or register a known device. Specifically, the systems disclosed herein may generate the device's “fingerprint” in an isolated and secured environment. Although the private key cannot be extracted from the isolated and secured environment, the authentication system can verify the truthfulness of the device's identity. This cryptographic “fingerprint,” in concert with a synchronous authentication system, has the ability to essentially eliminate authentication phishing. By ensuring that the cryptographic fingerprint of the device answering the synchronous authentication challenge has the same cryptographic fingerprint as the device that initiated the authentication request, the operation ensures the integrity of the authentication mechanism by verifying the legitimacy of the requesting device.