Identity Assurance Scoring for ID-Less Passwordless Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital authentication systems require users to remember multiple usernames and passwords, which is cumbersome and insecure, and federated identity management is cumbersome to set up and maintain.
Innovation Solution
A system that uses an identity assurance score server to authenticate users without IDs and passwords, generating a secret username and password for each service, and allows access through social single sign-on and social federation, using APIs to manage authentication factors based on a user's identity score.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional ID and password authentication is used, then user identification and access control are achieved, but security is compromised and maintenance burden increases
Solution Approach 1:
The patent extracts the authentication verification process from traditional ID/password databases and relocates it to blockchain-based smart contracts. Identity verification is separated into cryptographic proof mechanisms, eliminating the need for centralized password storage and manual account management while enhancing security through decentralized verification.
Solution Approach 2:
The patent introduces blockchain smart contracts as an intermediary layer between users and service providers. This mediator handles identity verification automatically through predefined cryptographic protocols, eliminating direct interaction with traditional authentication systems and reducing both security risks and operational complexity.
2Adaptability or versatility
If federated identity management is implemented, then partner access to internal applications is enabled, but initial setup and maintenance effort increases significantly
Solution Approach 1:
The patent implements a universal blockchain-based identity verification system that can serve multiple organizations and applications simultaneously. The same cryptographic identity framework works across different service providers and partners, eliminating the need for separate federated identity configurations for each partnership and reducing overall system complexity.
Solution Approach 2:
The patent performs identity verification setup in advance through blockchain network configuration and smart contract deployment. Once the blockchain identity system is established, partner access can be granted automatically through cryptographic key pairs without requiring ongoing configuration or manual setup for each new partner.
Data Source
AI summary
A technique is provided by which a user goes to a site and instead of the authentication system of the site going to their own databases to match an ID and password given by the user, because doing so is not secure, the site companies makes a call to an identity assurance score server (with ties to the ID-less and password-less system) and send a parameter such as a number. Then, based on that parameter (e.g., number or score), the identity assurance score server (with ties to the ID-less and password-less system, such as described hereinabove) sends a corresponding login protocol or factors to be satisfied to authenticate the user.


