Personal Digital Identity Device Hardware Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Password-based cloud service authentication in mobile devices is vulnerable to hacking, as hackers can gain access to user accounts by obtaining password files, compromising sensitive user information.
Innovation Solution
A personal digital identity device that communicates with mobile devices and cloud services using radio links, requiring user interaction through hardware-based methods such as button presses, fingerprint sensors, or motion sensors to authenticate, making security hardware available only after user interaction, thus enhancing security beyond password-only authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If password-based authentication is used, then ease of operation is improved, but security is worsened
Solution Approach 1:
The patent introduces a personal digital identity device as an intermediary between the user and the authentication system. This device stores cryptographic credentials and performs authentication operations, mediating the interaction between the user's mobile device and remote services. The intermediary device contains a processor, secure storage for cryptographic material, and optional biometric sensors, enabling secure authentication without exposing passwords.
Solution Approach 2:
The patent replaces the mechanical/password-based authentication system with a cryptographic system. Instead of relying on users to remember and enter passwords, the system uses cryptographic keys stored in secure element within the personal digital identity device. Authentication is performed through cryptographic proof of possession rather than secret sharing, substituting the mechanical act of typing passwords with electronic cryptographic verification.
2Reliability
If hardware-based authentication is implemented, then security is improved, but device complexity is worsened
Solution Approach 1:
The patent segments the authentication system into two parts: a lightweight personal digital identity device containing only essential cryptographic components (processor, secure storage, optional sensors), and the existing mobile device or remote server that handles application logic. This segmentation allows the security-critical functions to be isolated in a simple, dedicated device while keeping the overall system architecture modular and manageable.
Solution Approach 2:
The personal digital identity device is designed as a universal authentication token that can work with multiple different services and applications. The device contains generic cryptographic interfaces and can store multiple credential sets, enabling it to authenticate to various cloud services, mobile applications, and systems without requiring service-specific hardware or complex configuration. This multi-functionality reduces the need for multiple specialized devices.
Data Source
AI summary
A personal digital ID device provides a digital identifier to a service for a predetermined duration in response to user interaction. The user interaction may include a button press. The personal digital ID device may be in the form of a bracelet, a key fob, or other form factor. The service may be provided by a mobile device, in the cloud, or elsewhere.


