Identity Authentication via Trusted Intermediary Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current identity authentication methods, such as those based on public-key cryptography, fail to protect user privacy and do not provide adequate traceability, making it difficult to ensure privacy protection in applications where identity verification is necessary without exposing personal information.
Innovation Solution
A method, device, and system for identity authentication that involves a first authenticator, a second authenticator, and an authentication server, where the second authenticator completes anonymous authentication by transmitting verification results and identity authentication information through a security domain, allowing only the second authenticator and the authentication server to exchange information, thus protecting the privacy of the second authenticator.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional public-key cryptography authentication is used, then identity verification can be completed, but user privacy is exposed and identity information is disclosed to the authenticator
Solution Approach 1:
The patent introduces a trusted third-party authentication server as an intermediary between the user and the authenticator. The authentication server performs the actual identity verification using secure cryptographic protocols, while the authenticator only receives verification results. This mediator architecture allows identity verification to be completed without exposing the user's private identity information to the authenticator, thus resolving the contradiction between reliable authentication and privacy protection.
Solution Approach 2:
The authentication process is segmented into distinct functional components: the authentication client (user side), the authentication server (trusted third party), and the authenticator (verifying party). Each segment performs a specific function - the client initiates authentication, the server verifies identity securely, and the authenticator receives only the verification result. This segmentation allows the system to maintain reliability through proper verification while protecting privacy by limiting information exposure to only what is necessary.
2Loss of information
If anonymous authentication is implemented to protect privacy, then user identity is protected, but traceability is lost and control cannot be performed
Solution Approach 1:
The patent implements local quality by providing different levels of information visibility to different parties. The authentication server has access to full identity information for traceability purposes, while the authenticator only receives verification results without identity details. The user's private key remains secret on the client side. This differentiated information distribution allows the system to simultaneously achieve privacy protection for users, traceability for the trusted server, and verification capability for authenticators.
Solution Approach 2:
The trusted authentication server acts as an intermediary that maintains the connection between anonymous authentication and traceability. It receives authentication requests, performs verification using the user's private key, and records the authentication events for traceability. Meanwhile, it sends only verification results to authenticators, preserving user anonymity. The mediator thus enables both privacy protection and traceability by controlling information flow between different system components.
Data Source
AI summary
The present invention relates to the field of identity authentication. Provided are a method, device, and system for identity authentication, solving the technical problem that existing identity authentication technologies are incapable of protecting personal privacy, and that authentication technologies comprising personal privacy must provide a traceability feature. The method for identity authentication mainly comprises: a first authenticator transmitting to a second authenticator a first identity authentication message; the second authenticator transmitting to an authentication server a second identity authentication message; the authentication server verifying the validity of a secure domain where the second authenticator is at on the basis of the second identity authentication message; the authentication server returning to the second authenticator a third identity authentication message; when the third identity authentication message is received by the second authenticator, same transmitting to the first authenticator a fourth identity authentication message.


