Clickless Authentication Using Cryptographic Shares and Device Fingerprints
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods are vulnerable to time consumption, memorability issues, and security breaches due to password theft by adversaries, and require user interaction for verification, leading to inefficiencies and potential fraud.
Innovation Solution
A clickless authentication system using device fingerprints, cryptographic shares, and machine learning for fraud analysis, enabling secure user verification without user input, through a registration process involving device fingerprint extraction, cryptographic object generation, and dynamic share distribution among user device, authentication server, and escrow server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods (passwords, OTPs) are used, then user verification can be performed, but security is compromised due to password theft by adversaries
Solution Approach 1:
The authentication credential is segmented into multiple cryptographic shares that are distributed across different locations (user device, authentication server, and potentially third-party servers). No single entity possesses the complete credential, making it impossible for adversaries to steal the full authentication data from a single point of compromise.
Solution Approach 2:
The patent introduces cryptographic intermediaries and trusted third-party servers that mediate the authentication process. These intermediaries hold partial cryptographic shares and verify authentication requests without exposing the complete credential, adding layers of security against direct attacks on user credentials.
2Productivity
If users manually enter passwords or OTPs, then authentication can be performed, but time consumption increases due to repetition and potential errors
Solution Approach 1:
The system implements self-service authentication where the user device automatically performs cryptographic verification using stored shares and received verification data. The authentication process occurs without manual user input for credential entry, as the device autonomously completes the verification protocol, dramatically reducing authentication time.
Solution Approach 2:
Cryptographic shares are pre-distributed and stored in the user device during an initial setup phase. When authentication is needed, the device already possesses the necessary credentials and can immediately perform verification without requiring users to recall or manually enter passwords, enabling instant authentication.
3Reliability
If cryptographic shares are distributed among multiple servers, then security is improved, but device complexity increases
Solution Approach 1:
The patent employs universal cryptographic protocols and standardized share distribution mechanisms that can be implemented across different server architectures and platforms. The core cryptographic operations remain consistent regardless of the number or type of servers involved, allowing the system to scale without proportionally increasing operational complexity.
Data Source
AI summary
Methods and systems for performing secure clickless authentication. Embodiments herein disclose a registration process, and an authentication process for at least one user, who wants to perform at least one web-based transaction using at least one application, wherein the registration process is performed using at least one user input, and the authentication process is performed without using any user inputs/gestures. The registration process involves generating cryptographic shares by validating the user, based on at least one of, the device fingerprint of the user device, the device numbers/mobile numbers associated with the user and multiple cryptographic objects. The authentication process involves authenticating the user based on the static or dynamically generated cryptographic shares during the registration process and subsequent authentication processes.


