Device Identity System Using Trust Score for Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current online authentication methods, such as multi-factor identification using SMS or biometrics, lack flexibility and convenience, burdening both users and service providers, and often rely on vulnerable knowledge factors that are difficult to remember and prone to exposure.
Innovation Solution
A device identity system that uses a hardware root of trust and external contextual tests to provide a trust score for device identification, allowing users to configure diverse identification factors and reduce reliance on passwords, enabling secure and convenient access to online services without imposing rigid authentication requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multi-factor authentication protocols are implemented, then security is improved, but device complexity and ease of operation deteriorate
Solution Approach 1:
The patent introduces a session handler as an intermediary component that coordinates between the trust scoring engine, identity service, and third-party service providers. This mediator manages the authentication flow, collects context verification data, and computes trust scores, thereby reducing the complexity burden on individual devices while maintaining strong multi-factor authentication security through centralized coordination.
2Reliability
If rigid authentication requirements are imposed, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent implements dynamic authentication where the trust score threshold and required context verification factors are not fixed but adapt based on the specific service, user risk profile, and detected threats. The session handler can adjust authentication requirements in real-time, allowing flexible security policies that maintain high security for sensitive operations while providing convenient access for low-risk scenarios, thereby resolving the contradiction between rigid security requirements and user convenience.
3Ease of operation
If knowledge factors are used for authentication, then ease of operation is improved, but reliability deteriorates due to vulnerability to exposure
Solution Approach 1:
The patent merges knowledge factors (something the user knows) with possession factors (something the user has, such as device identifiers) and inherence factors (something the user is, such as behavioral patterns) into a unified trust score calculation. The session handler combines multiple context verification factors including but not limited to passwords, device IDs, location data, and usage patterns, so that no single knowledge factor is sufficient for authentication, thereby maintaining ease of operation while significantly improving security by eliminating the vulnerability of relying on isolated knowledge factors.
4Adaptability or versatility
If diverse identification factors are configured by users, then adaptability is improved, but device complexity deteriorates
Solution Approach 1:
The patent implements self-service functionality where the session handler and trust scoring engine automatically collect, verify, and evaluate context verification factors without requiring manual user configuration. The system autonomously gathers device identifiers, location information, usage patterns, and other context data, then computes trust scores based on pre-defined policies. This automation provides users with adaptable authentication experiences while eliminating the complexity of manual configuration, as the system self-adjusts to different services and scenarios based on embedded policies rather than user setup.
Data Source
AI summary
Device identification scoring systems and methods may be provided that can increase the reliability and security of communications between devices and service providers. Users may select and configure additional identification factors that are unique and convenient for them. These factors, along with additional environmental variables, feed into a trust score computation that weights the trustworthiness of the device context requesting communication with a service provider. Service providers rely on the trust score rather than enforce a specific identification routine themselves. A combination of identification factors selected by the user can be aggregated together to produce a trust score high enough to gain access to a given online service provider. A threshold of identification risk may be required to access a service or account provided by the online service provider.


