Personal Digital Identity Device Hardware Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Password-based cloud service authentication in mobile devices is vulnerable to hacking, as hackers can gain access to user accounts by obtaining password files, compromising sensitive user information.

Innovation Solution

A personal digital identity device that communicates with mobile devices and cloud services using radio links, requiring user interaction through hardware-based methods such as button presses, fingerprint sensors, or motion sensors to authenticate, making security hardware available only after user interaction, thus enhancing security beyond password-only authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If password-based authentication is used, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a personal digital identity device as an intermediary between the user and the authentication system. This device stores cryptographic credentials and performs authentication operations, mediating the interaction between the user's mobile device and remote services. The intermediary device contains a processor, secure storage for cryptographic material, and optional biometric sensors, enabling secure authentication without exposing passwords.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/password-based authentication system with a cryptographic system. Instead of relying on users to remember and enter passwords, the system uses cryptographic keys stored in secure element within the personal digital identity device. Authentication is performed through cryptographic proof of possession rather than secret sharing, substituting the mechanical act of typing passwords with electronic cryptographic verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If hardware-based authentication is implemented, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into two parts: a lightweight personal digital identity device containing only essential cryptographic components (processor, secure storage, optional sensors), and the existing mobile device or remote server that handles application logic. This segmentation allows the security-critical functions to be isolated in a simple, dedicated device while keeping the overall system architecture modular and manageable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The personal digital identity device is designed as a universal authentication token that can work with multiple different services and applications. The device contains generic cryptographic interfaces and can store multiple credential sets, enabling it to authenticate to various cloud services, mobile applications, and systems without requiring service-specific hardware or complex configuration. This multi-functionality reduces the need for multiple specialized devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9154500B2Personal digital identity device with microphone responsive to user interaction
Publication Date: 2015.10.06 SIDEASSURE INC
  • US9154500B2 patent drawing
  • US9154500B2 patent drawing
  • US9154500B2 patent drawing

AI summary

A personal digital ID device provides a digital identifier to a service for a predetermined duration in response to user interaction. The user interaction may include a button press. The personal digital ID device may be in the form of a bracelet, a key fob, or other form factor. The service may be provided by a mobile device, in the cloud, or elsewhere.