Digital Identity Binding for Secure Online Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current online authentication processes for financial transactions, particularly in secure remote commerce, require multiple user credentials and authentication steps, leading to inefficiencies and increased risk of data compromise, especially when interacting with multiple systems during online checkout processes.
Innovation Solution
A method of establishing a digital identity by partially enrolling it to computer hardware and using user authentication to bind the identity, allowing a single authentication process to complete enrollment and authenticate for online services, such as Secure Remote Commerce, through mechanisms like 3D Secure, enabling 'backward' or 'forward' trust transfer depending on availability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple authentication steps and credentials are required for online transactions, then security is improved, but user experience and processing efficiency deteriorate
Solution Approach 1:
The patent combines multiple authentication steps into a single unified authentication process. The system performs both enrollment authentication and transaction authentication simultaneously, merging what were previously separate credential verification steps into one consolidated authentication event, thereby maintaining security while improving user experience
Solution Approach 2:
The authentication system is designed to serve multiple functions: it performs both enrollment verification and transaction authorization in a single process. This multi-functional approach allows the same authentication mechanism to handle different security requirements without requiring separate authentication flows for each function
2Reliability
If multiple authentication steps and credentials are required for online transactions, then security is improved, but processing time and complexity increase
Solution Approach 1:
The patent merges enrollment authentication and transaction authentication into a single simultaneous process. By combining these authentication events, the system eliminates the sequential time required for separate authentication steps, reducing total processing time while maintaining the security requirements of both functions
Solution Approach 2:
The system performs preliminary binding of the digital identity to the user's device during the unified authentication process. This preliminary action establishes the authentication context in advance, allowing subsequent transactions to proceed without requiring additional authentication steps, thereby reducing processing time
3Reliability
If multiple credentials are required for authentication, then security against data compromise is improved, but the risk of credential exposure and system vulnerability increases
Solution Approach 1:
The patent extracts the credential verification process from multiple separate systems and consolidates it into a single authentication event. By taking out the authentication logic from distributed systems and centralizing it, the system reduces the number of credential exposure points and minimizes the attack surface for potential data compromise
Solution Approach 2:
The system merges multiple authentication credentials and verification steps into a single unified authentication process. This consolidation reduces the total number of credential handling operations across multiple systems, thereby decreasing the cumulative risk of credential exposure and system vulnerability
Data Source
AI summary
A method of establishing a digital identity for use of an online service and of subsequently using the digital identity to perform the online service is described. A digital identity for the online service is bound to computer hardware associated with the digital identity. A user associated with the digital identity provides a user authentication at the computer hardware associated with the digital identity. The digital identity is enrolled for the online service, and a first instance of the online service for the digital identity is performed. A common user authentication process result completes enrolment of the digital identity and authenticates the digital identity for performing said first instance of the online service.


