Local Authentication Device Persona Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods, such as username and password combinations, are vulnerable to interception, theft, and brute force attacks, compromising security and privacy.
Innovation Solution
An authentication device that performs local authentication, generating an authentication result indicating the identity and attributes of the entity, such as manufacturer, model, and capabilities, to enable risk-based decisions by relying parties while maintaining privacy through local processing and cryptographically secure persona management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If username and password are communicated from user to relying party, then authentication can be performed, but security is compromised due to interception and theft risks
Solution Approach 1:
The patent extracts the authentication result and device attributes from the authentication process, transmitting only these minimal necessary data elements rather than the full authentication credentials. This removes the vulnerable password transmission while maintaining authentication functionality.
Solution Approach 2:
The authentication device acts as an intermediary between the user and relying party, performing local authentication and presenting credentials without exposing the user's password. This mediator architecture prevents direct password transmission while enabling secure authentication.
2Reliability
If authentication device indicates detailed attributes to relying party, then risk-based decisions can be made, but privacy is reduced due to information disclosure
Solution Approach 1:
The patent applies local quality by indicating only specific authentication device attributes (such as device type, security capabilities, and authentication method used) rather than comprehensive user information. This provides relying parties with sufficient risk assessment data while maintaining user privacy through selective information disclosure.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An identity of an entity (120) is authenticated at an authentication device (110) using at least one authentication process. The result of the authentication is indicated. The authentication result identifies at least the identity of the entity (120) and the at least one authentication process used to authenticate the identity of the entity (120).