Local Authentication Device Persona Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods, such as username and password combinations, are vulnerable to interception, theft, and brute force attacks, compromising security and privacy.

Innovation Solution

An authentication device that performs local authentication, generating an authentication result indicating the identity and attributes of the entity, such as manufacturer, model, and capabilities, to enable risk-based decisions by relying parties while maintaining privacy through local processing and cryptographically secure persona management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If username and password are communicated from user to relying party, then authentication can be performed, but security is compromised due to interception and theft risks

Engineering Contradiction:
Improveauthentication securityVSAvoiddata interception and theft
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication result and device attributes from the authentication process, transmitting only these minimal necessary data elements rather than the full authentication credentials. This removes the vulnerable password transmission while maintaining authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication device acts as an intermediary between the user and relying party, performing local authentication and presenting credentials without exposing the user's password. This mediator architecture prevents direct password transmission while enabling secure authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication device indicates detailed attributes to relying party, then risk-based decisions can be made, but privacy is reduced due to information disclosure

Engineering Contradiction:
Improverisk assessment accuracyVSAvoiduser privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies local quality by indicating only specific authentication device attributes (such as device type, security capabilities, and authentication method used) rather than comprehensive user information. This provides relying parties with sufficient risk assessment data while maintaining user privacy through selective information disclosure.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2959420B1Methods, apparatus and computer programs for entity authentication
Publication Date: 2019.09.11 SIMMONDS PAUL
  • EP2959420B1 patent drawingFigure 1
  • EP2959420B1 patent drawingFigure 2
  • EP2959420B1 patent drawingFigure 3

AI summary

An identity of an entity (120) is authenticated at an authentication device (110) using at least one authentication process. The result of the authentication is indicated. The authentication result identifies at least the identity of the entity (120) and the at least one authentication process used to authenticate the identity of the entity (120).