Device Watermark Identity Recognition for Secure Service Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity methods fail to provide conclusive proof of user identity recognition and affiliation, leading to vulnerabilities in modern cyber threats, such as data breaches and advanced persistent attacks, where compromised user credentials can result in unauthorized access and data breaches.

Innovation Solution

A system and method that uses a device watermark associated with the user's device, combined with a service identifier, to provide authoritative identity recognition and affiliation, generating a user token with a dynamically computed affiliation score and attributes, which is transmitted over a secure encrypted channel, eliminating the need for external physical devices and enhancing authentication security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional password-based authentication is used, then users can access services, but user credentials can be compromised leading to unauthorized access and data breaches

Engineering Contradiction:
Improveauthentication securityVSAvoidcredential compromise risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a broker service as an intermediary between the user device and the accessed service. The broker verifies device watermarks and service identifiers, and issues user tokens that mediate the authentication process. This intermediary layer prevents direct credential exposure and enables verification of device identity without relying on traditional passwords.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces physical authentication artifacts (like key fobs or smart cards) with virtual copies in the form of device watermarks embedded in the device's system memory. These virtual copies serve the same authentication function without requiring external physical devices, reducing attack surfaces while maintaining security.

Inventive Principle:
Principle #26Copying

2Reliability

If multi-factor authentication with physical devices is used, then authentication security is improved, but device complexity and user burden increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The device watermark serves multiple functions: it authenticates the device identity, enables secure communication with the broker, and provides the basis for issuing user tokens. This single embedded artifact replaces multiple separate authentication mechanisms (passwords, physical key fobs, biometric devices), reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If device watermarking is implemented, then proof of device identity is provided, but system complexity increases due to watermark generation and verification

Engineering Contradiction:
Improvedevice identity verificationVSAvoidwatermark management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The device watermark is self-generated by the device itself using its existing system memory and hardware identifiers. The watermark embeds the device's unique characteristics without requiring external programming or configuration. This self-service approach eliminates the need for complex enrollment processes and reduces the burden on system administrators.

Inventive Principle:
Principle #25Self-service

4Reliability

If user affiliation and dynamic scoring are implemented, then user behavior recognition is improved, but information processing requirements increase

Engineering Contradiction:
Improveuser behavior recognitionVSAvoiddata processing load
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system implements dynamic affiliation scoring by evaluating only the most relevant user attributes and device characteristics for each authentication request, rather than processing all possible data points. The broker computes affiliation scores based on the specific context of each transaction, processing only the necessary subset of information required for that particular verification.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9503452B1System and method for identity recognition and affiliation of a user in a service transaction
Publication Date: 2016.11.22 KUMAR SRINIVAS
  • US9503452B1 patent drawing
  • US9503452B1 patent drawing
  • US9503452B1 patent drawing

AI summary

The method integrates the dynamic and authoritative posture of an authenticated user, a registered device, and a registered service provider as a conclusive proof of identity recognition for affiliation of associated contextual attribution and referential integrity. In addition to relieving the user of the burden of remembering multiple passwords for a plurality of services, the method provides a means to facilitate an affiliation oriented architecture for a broad spectrum of web and cloud based services with affiliation aware content streaming, leveraging the affiliation score as a key trust metric. The method provides protection from user-agnostic delegation and impersonation of identity, social engineering, and compromised passwords, which are exploited by numerous strains of landed malware to launch multi-stage coordinated cyber-attacks on consumer accounts and enterprise systems. The method of affiliation based on identity recognition provides authoritative, contextual, and consensual user information, of relevance in a live transaction, to the service provider.