Hosted FIDO Authenticator for Multi-User Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large organizations like hospitals, providing separate authenticators for each individual is costly and complex due to the need for multiple entry points and extensive infrastructure for secure access systems, making it impractical to implement passwordless authentication using dedicated hardware security keys.
Innovation Solution
A system and method for hosting FIDO authenticators on a local network or cloud using Hardware Security Modules (HSM) that utilizes short-range wireless communication, such as RFID tags or access cards, to uniquely identify users and bind them to their associated authenticators, enabling passwordless authentication without the need for dedicated hardware security keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate authenticators are provided for each user, then authentication security is improved, but system cost and complexity increase
Solution Approach 1:
The patent merges multiple individual authenticator functions into a single shared authenticator that can service multiple users. The authenticator is configured to receive authentication requests from multiple readers and maintain separate credential verification for each user, eliminating the need for separate hardware authenticators for each user while maintaining security.
Solution Approach 2:
The shared authenticator is designed with multi-functionality to handle authentication requests from multiple different users and multiple different readers. It maintains separate credential storage and verification processes for each user, allowing a single device to perform the work of multiple dedicated authenticators.
2Speed
If authentication information is stored in each reader, then authentication speed is improved, but system cost and maintenance complexity increase
Solution Approach 1:
The patent extracts the authentication information storage function from the readers and centralizes it in a single shared authenticator. The readers are reduced to simple signal transmission devices that forward authentication requests to the shared authenticator, which maintains and verifies all credential information for multiple users.
Solution Approach 2:
The shared authenticator acts as an intermediary between multiple readers and the credential verification process. Instead of each reader independently storing and verifying credentials, the shared authenticator receives requests from any reader, performs the verification using stored credentials, and returns the authentication result, simplifying the reader devices while maintaining authentication capability.
3Adaptability or versatility
If readers are connected to a central authentication unit, then centralized control is improved, but installation cost and complexity increase
Solution Approach 1:
The shared authenticator serves as a universal authentication unit that can service multiple readers without requiring individual connections to a central system. It handles authentication requests from any connected reader through wireless communication, providing centralized control functionality while eliminating the need for complex wired infrastructure.
Solution Approach 2:
The patent replaces the mechanical wired connection system with wireless communication technology. Readers communicate with the shared authenticator wirelessly, eliminating the need for physical cable installations between readers and the central authentication unit, thereby reducing installation complexity and cost while maintaining centralized control capability.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach allows for efficient and cost-effective implementation of passwordless authentication in shared multi-user environments by using HSM-based authenticators and RFID or access card identifiers, simplifying the authentication process and reducing infrastructure costs.
Implementation Method 1
the connected device has a reader and application programming interface that provides the unique identifier to the application service using a communication link on the computing device, the connected device configured to detect the unique identifier via short-range wireless communication
Data Source
AI summary
A system or method for hosting and managing FIDO authenticators in local network or cloud for users in a shared multi-user environment; which receives an authentication request initiated by a relying party application on a computing device via Web Authentication (WebAuthn) interface; and uses unique identifiers (such as RFID tags) to distinguish the hosted authenticators associated with each user to forward the authentication request; and receiving a response to that authentication request from the hosted authenticator on the local network or cloud; and transmitting the authentication response back to the sender application on the computing device for authentication purposes.


