Dynamic Digital Identification for Identity Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current identity authentication methods, such as digital signatures, are ineffective in non-face-to-face communications due to issues like data format changes and semantic interpretation differences, leading to vulnerabilities in 'phishing', 'pharming', and 'man-in-the-middle' attacks, especially in open environments like the Internet.
Innovation Solution
A dynamic digital identification system using an encrypted character string related to the communicating entity, encrypted with a private/public key pair, which is conditionally valid and can be verified by both humans and machines, ensuring message integrity and preventing misuse.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital signature method is used for identity authentication, then the sender's identity can be theoretically authenticated and message integrity can be assured, but the verification is not easy and the method is affected by many factors such as data format changes and semantic interpretation differences
Solution Approach 1:
The patent segments the digital identification into multiple components: an encrypted portion containing the entity's identity information and a non-encrypted portion containing verification data. This segmentation allows the verification portion to be easily checked by recipients while the encrypted portion maintains security, thus resolving the contradiction between authentication reliability and verification ease.
Solution Approach 2:
The patent introduces a hash function as an intermediary mechanism that transforms the encrypted identification into a verifiable format. The hash function enables easy verification by recipients without compromising the security of the encrypted identification, thereby resolving the contradiction between reliable authentication and ease of verification.
2Reliability
If digital signature is used to authenticate sender identity, then the sender cannot deny sending the message, but e-mail systems may add symbols including whitespaces which invalidate the digital signature
Solution Approach 1:
The patent creates a dynamic digital identification that is generated fresh for each communication instance rather than using a static signature. This dynamic approach allows the identification to adapt to different e-mail system variations and formatting, maintaining both non-repudiation and compatibility with various e-mail systems.
Solution Approach 2:
The patent changes the parameter of the digital identification from a fixed, immutable signature to a dynamic, regeneratable identification. By including elements like timestamps and session-specific data, the identification can accommodate different e-mail system formats while maintaining its authentication and non-repudiation properties.
3Measurement precision
If digital signature verifies only the syntax of data but not the semantics, then the data bit streams can be same at sending and receiving end, but the presentations and meanings could be different due to different system interpretations
Solution Approach 1:
The patent performs preliminary encoding of the digital identification in a standardized format before transmission. This preliminary action ensures that the identification is encoded in a way that is consistent across different systems, addressing both syntax verification and semantic interpretation reliability by establishing a common encoding standard before the data encounters different system interpretations.
Data Source
AI summary
Used in a communication involving Entity 1 and Entity 2 to authenticate Entity 1's identity, a digital identification of Entity 1 comprises an encrypted character string wherein the string is related to Entity 2 and is directly or indirectly encrypted with a key in a private/public key pair of Entity 1's. Such digital identification is dynamic and can be used as one-time or multiple-time identification. Such digital identification of an entity allows for the entity's being authenticated by another entity without the two entities having a one-to-one communication in advance. Also such a digital identification does not rely on the syntax of other messages or data as does a digital signature do and can be verified easily. The verification of such a digital identification can be easily confirmed by both human beings and machines.


