Authenticator Endorsement for Cross-App Credential Sync
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems face challenges in efficiently managing and synchronizing authentication credentials across multiple devices and platforms, leading to user inconvenience and security risks, particularly in scenarios like electronic payments where friction and security are critical.
Innovation Solution
The system enables seamless endorsement and synchronization of user verification reference data across authenticators tied to the same platform, using FIDO authentication technology to reduce the need for per-app registration and enhance security, while allowing secure sharing and synchronization of authentication credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users register separate authenticators for each merchant or app, then security can be maintained per application, but user friction increases and convenience deteriorates
Solution Approach 1:
The patent implements a universal authenticator system where a single authenticator can be endorsed to multiple relying parties (merchants/apps). The authenticator contains platform identification data that allows it to prove its identity to multiple different services without requiring separate registration for each one, thus achieving multi-functionality while maintaining security.
Solution Approach 2:
The patent introduces a platform as an intermediary between the authenticator and multiple relying parties. The platform holds endorsement data that verifies the authenticator's identity and authorizes it to access multiple services. This intermediary approach allows the authenticator to work across different applications without direct registration with each one, reducing user friction while maintaining security through the platform's verification.
2Ease of operation
If authentication credentials are shared across multiple platforms, then user convenience improves, but security risks increase due to potential credential compromise
Solution Approach 1:
The patent segments authentication credentials by separating the authenticator identity from specific relying party credentials. The authenticator contains platform identification data rather than individual merchant credentials. This segmentation allows the authenticator to be shared across multiple platforms while each relying party maintains its own security verification through the platform's endorsement data, thus enabling credential sharing without proportionally increasing security risks.
3Reliability
If per-app registration is implemented, then security control is precise, but device complexity and registration overhead increase
Solution Approach 1:
The patent merges multiple registration operations into a single endorsement process. Instead of requiring separate registration with each relying party, the system combines authentication and authorization into one step where the platform verifies the authenticator and generates endorsement data that works across multiple services. This reduces registration overhead while maintaining security control through the platform's centralized verification.
Data Source
AI summary
A system, apparatus, method, and machine-readable medium are described for endorsing authenticators. For example, one embodiment of an apparatus comprises: a first instance of an authenticator associated with a first app to allow a user of the first app to authenticate with a first relying party; a secure key store accessible by the first instance of the authenticator to securely store authentication data related to the first app; and a synchronization processor to share at least a portion of the authentication data with a second instance of the authenticator associated with a second app to be executed on the apparatus.


