Passwordless Authentication via Icon-Formula Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current online identity systems are inadequate in protecting against espionage and cybercrime due to their reliance on username and password combinations, which are stored on servers, making them vulnerable to breaches.

Innovation Solution

A system and method that eliminates the need for usernames and passwords by generating mathematical formulas associated with a user and client device profile, where the user selects a sequence of icons linked to these formulas, and the server generates a decryption key based on the results, ensuring that authentication occurs without storing credentials on either the client or server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If username and password systems are used for authentication, then ease of operation is improved, but security is worsened due to stored credentials being vulnerable to breaches

Engineering Contradiction:
Improveauthentication processVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts and eliminates the vulnerable credential storage component from the authentication system. Instead of storing usernames and passwords on the server, the system uses device-specific cryptographic keys and mathematical formulas that are computed locally on the user's device. This removes the attack surface associated with credential databases while maintaining authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces the traditional mechanical credential verification system (comparing stored passwords with user input) with a cryptographic mathematical system. The server stores mathematical formulas and receives cryptographic proofs from devices, substituting the password-matching mechanism with public-key cryptography and zero-knowledge proof concepts, thereby eliminating the need to store secret credentials.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If biometric authentication is implemented, then security is improved compared to passwords, but the system still relies on token matching which is vulnerable

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a cryptographic copy of the authentication mechanism that resides on the user's device rather than the server. The device contains cryptographic keys and computational logic that replicate the authentication verification process locally, eliminating the need to transmit or store sensitive credential data on the server while maintaining security.

Inventive Principle:
Principle #26Copying

3Device complexity

If server stores user credentials, then authentication verification is simplified, but vulnerability to cybercrime increases

Engineering Contradiction:
Improveauthentication systemVSAvoidcybercrime vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent removes the credential storage function from the server entirely. The server stores only public keys and mathematical formulas, while the private keys and sensitive authentication data remain exclusively on the user's device. This extraction eliminates the centralized vulnerability point that attackers target in traditional authentication systems.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements preliminary cryptographic binding between the device and authentication credentials during device provisioning. The device's hardware identity is cryptographically bound to authentication keys before use, preventing unauthorized copying or transfer of credentials to other devices. This preliminary anti-action prevents credential theft and replay attacks before they can occur.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11496586B2User and client device registration with server
Publication Date: 2022.11.08 SWENGLER PAUL
  • US11496586B2 patent drawing
  • US11496586B2 patent drawing
  • US11496586B2 patent drawing

AI summary

Disclosed are systems and methods for registering a user and/or a client device with a server computer. In one embodiment, a registration method does not use any stored passwords or tokens. In certain embodiments, a method can include (a) generating a plurality of mathematical formulas, at least some of the plurality of mathematical formulas comprising variables; (b) generating a user ID file name comprising a decryption key, the decryption key associated with the plurality of mathematical formulas; (c) generating a plurality of icons; (d) assigning uniquely each mathematical formula from the plurality of mathematical formulas to each of the icons of the plurality of icons; and (e) receiving an ordered selection of icons, the ordered selection of icons selected by the user from said plurality of icons.