Hosted FIDO Authenticator for Multi-User Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large organizations like hospitals, providing separate authenticators for each individual is costly and complex due to the need for multiple entry points and extensive infrastructure for secure access systems, making it impractical to implement passwordless authentication using dedicated hardware security keys.

Innovation Solution

A system and method for hosting FIDO authenticators on a local network or cloud using Hardware Security Modules (HSM) that utilizes short-range wireless communication, such as RFID tags or access cards, to uniquely identify users and bind them to their associated authenticators, enabling passwordless authentication without the need for dedicated hardware security keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate authenticators are provided for each user, then authentication security is improved, but system cost and complexity increase

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple individual authenticator functions into a single shared authenticator that can service multiple users. The authenticator is configured to receive authentication requests from multiple readers and maintain separate credential verification for each user, eliminating the need for separate hardware authenticators for each user while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared authenticator is designed with multi-functionality to handle authentication requests from multiple different users and multiple different readers. It maintains separate credential storage and verification processes for each user, allowing a single device to perform the work of multiple dedicated authenticators.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Speed

If authentication information is stored in each reader, then authentication speed is improved, but system cost and maintenance complexity increase

Engineering Contradiction:
Improveauthentication speedVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent extracts the authentication information storage function from the readers and centralizes it in a single shared authenticator. The readers are reduced to simple signal transmission devices that forward authentication requests to the shared authenticator, which maintains and verifies all credential information for multiple users.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The shared authenticator acts as an intermediary between multiple readers and the credential verification process. Instead of each reader independently storing and verifying credentials, the shared authenticator receives requests from any reader, performs the verification using stored credentials, and returns the authentication result, simplifying the reader devices while maintaining authentication capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If readers are connected to a central authentication unit, then centralized control is improved, but installation cost and complexity increase

Engineering Contradiction:
Improvecentralized controlVSAvoidinstallation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The shared authenticator serves as a universal authentication unit that can service multiple readers without requiring individual connections to a central system. It handles authentication requests from any connected reader through wireless communication, providing centralized control functionality while eliminating the need for complex wired infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent replaces the mechanical wired connection system with wireless communication technology. Readers communicate with the shared authenticator wirelessly, eliminating the need for physical cable installations between readers and the central authentication unit, thereby reducing installation complexity and cost while maintaining centralized control capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach allows for efficient and cost-effective implementation of passwordless authentication in shared multi-user environments by using HSM-based authenticators and RFID or access card identifiers, simplifying the authentication process and reducing infrastructure costs.

Implementation Method 1

the connected device has a reader and application programming interface that provides the unique identifier to the application service using a communication link on the computing device, the connected device configured to detect the unique identifier via short-range wireless communication

Methodology Applied
Scientific EffectRFID (Radio Frequency Identification): Electromagnetic Induction

Data Source

PatentUS11930006B2System and method for hosting FIDO authenticators
Publication Date: 2024.03.12 IDMELON TECH INC
  • US11930006B2 patent drawing
  • US11930006B2 patent drawing
  • US11930006B2 patent drawing

AI summary

A system or method for hosting and managing FIDO authenticators in local network or cloud for users in a shared multi-user environment; which receives an authentication request initiated by a relying party application on a computing device via Web Authentication (WebAuthn) interface; and uses unique identifiers (such as RFID tags) to distinguish the hosted authenticators associated with each user to forward the authentication request; and receiving a response to that authentication request from the hosted authenticator on the local network or cloud; and transmitting the authentication response back to the sender application on the computing device for authentication purposes.