Credential Broker Hashed Authentication Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems for online identities and credentials lack robustness in ensuring assurance levels, particularly in networked environments, which can lead to security risks, especially in financial and national security transactions.

Innovation Solution

A system and method for secure online credential authentication involving a credential broker that receives identification information, hashes it, and compares it to stored hashed data, ensuring secure storage and transmission without maintaining personal identifiable information, thereby providing a trusted authentication process aligned with requested assurance levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If personal identifiable information is stored for authentication, then authentication reliability is improved, but security risk and privacy vulnerability increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts and removes personal identifiable information (PII) from the authentication system by using hashed identifiers instead. The system stores and processes only hashed values that cannot be reverse-engineered to reveal original personal data, thereby eliminating the security vulnerability while maintaining authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces hashed identifiers as an intermediary between the user's personal information and the authentication system. This intermediary layer allows verification of user identity without exposing actual personal data, resolving the contradiction between reliable authentication and security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If hashed identification information is stored instead of personal information, then security and privacy are improved, but authentication complexity increases

Engineering Contradiction:
Improvesecurity riskVSAvoidauthentication complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-hashing personal identifiers before storage and authentication. The system pre-processes personal information into hashed form during user registration, eliminating the need for complex real-time hashing operations during authentication and simplifying the overall process.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If traditional authentication systems are used, then ease of operation is maintained, but assurance levels for high-risk transactions are insufficient

Engineering Contradiction:
Improveease of authenticationVSAvoidassurance level
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent creates a universal authentication system using hashed identifiers that can serve multiple functions and assurance levels. The same hashed identifier mechanism works for both low-risk and high-risk transactions, providing scalable security without requiring different systems for different operation complexities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240430260A1Systems and methods for secure online credential authentication
Publication Date: 2024.12.26 ID ME
  • US20240430260A1 patent drawing
  • US20240430260A1 patent drawing
  • US20240430260A1 patent drawing

AI summary

Systems, methods, and non-transitory computer-readable medium are disclosed includes for secure online credential authentication. One method includes receiving, over an electronic network, identification information from an identity provider; accessing, from a database, previously stored hashed identification information stored in association with a previous identity provider; comparing the identification information to previously stored hashed identification information; and storing the identification information in association with the identity provider that provided the identification information in the database when the hashed identification information does not match previously stored hashed identification information.