Identity Authentication via Trusted Intermediary Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity authentication methods, such as those based on public-key cryptography, fail to protect user privacy and do not provide adequate traceability, making it difficult to ensure privacy protection in applications where identity verification is necessary without exposing personal information.

Innovation Solution

A method, device, and system for identity authentication that involves a first authenticator, a second authenticator, and an authentication server, where the second authenticator completes anonymous authentication by transmitting verification results and identity authentication information through a security domain, allowing only the second authenticator and the authentication server to exchange information, thus protecting the privacy of the second authenticator.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional public-key cryptography authentication is used, then identity verification can be completed, but user privacy is exposed and identity information is disclosed to the authenticator

Engineering Contradiction:
Improveidentity verificationVSAvoiduser privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a trusted third-party authentication server as an intermediary between the user and the authenticator. The authentication server performs the actual identity verification using secure cryptographic protocols, while the authenticator only receives verification results. This mediator architecture allows identity verification to be completed without exposing the user's private identity information to the authenticator, thus resolving the contradiction between reliable authentication and privacy protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into distinct functional components: the authentication client (user side), the authentication server (trusted third party), and the authenticator (verifying party). Each segment performs a specific function - the client initiates authentication, the server verifies identity securely, and the authenticator receives only the verification result. This segmentation allows the system to maintain reliability through proper verification while protecting privacy by limiting information exposure to only what is necessary.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If anonymous authentication is implemented to protect privacy, then user identity is protected, but traceability is lost and control cannot be performed

Engineering Contradiction:
Improveuser privacy protectionVSAvoidtraceability
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent implements local quality by providing different levels of information visibility to different parties. The authentication server has access to full identity information for traceability purposes, while the authenticator only receives verification results without identity details. The user's private key remains secret on the client side. This differentiated information distribution allows the system to simultaneously achieve privacy protection for users, traceability for the trusted server, and verification capability for authenticators.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The trusted authentication server acts as an intermediary that maintains the connection between anonymous authentication and traceability. It receives authentication requests, performs verification using the user's private key, and records the authentication events for traceability. Meanwhile, it sends only verification results to authenticators, preserving user anonymity. The mediator thus enables both privacy protection and traceability by controlling information flow between different system components.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10291614B2Method, device, and system for identity authentication
Publication Date: 2019.05.14 CHINA IWNCOMM
  • US10291614B2 patent drawing
  • US10291614B2 patent drawing
  • US10291614B2 patent drawing

AI summary

The present invention relates to the field of identity authentication. Provided are a method, device, and system for identity authentication, solving the technical problem that existing identity authentication technologies are incapable of protecting personal privacy, and that authentication technologies comprising personal privacy must provide a traceability feature. The method for identity authentication mainly comprises: a first authenticator transmitting to a second authenticator a first identity authentication message; the second authenticator transmitting to an authentication server a second identity authentication message; the authentication server verifying the validity of a secure domain where the second authenticator is at on the basis of the second identity authentication message; the authentication server returning to the second authenticator a third identity authentication message; when the third identity authentication message is received by the second authenticator, same transmitting to the first authenticator a fourth identity authentication message.