Mobile Trust Broker Proximity Identity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for identifying individuals and validating their credentials, such as relying on claims, introductions, documents, and electronic badges, are unreliable due to the risk of deception, forgery, and loss or theft, leading to a need for a more secure and reliable verification system.
Innovation Solution
A system utilizing mobile devices and proximity-based communications channels to verify identity assertions made by a trusted authority, which authenticates entities using knowledge-based or biometric techniques and cryptographically signs assertions to prevent tampering, ensuring that the identity validation is conditional on a specific contextual relationship between devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional methods (claims, introductions, documents, electronic badges) are used for identity verification, then the process is simple and quick, but the reliability and security of verification deteriorates due to risks of deception, forgery, and loss or theft
Solution Approach 1:
The patent introduces a trusted authority as an intermediary that issues cryptographically signed assertions about entity identities. This mediator resolves the contradiction by providing reliable verification through cryptographic signatures while keeping the actual verification process simple for end users, who only need to validate signatures rather than manually verify documents or credentials
Solution Approach 2:
The patent replaces manual mechanical verification processes (examining physical documents, checking badges, human judgment) with cryptographic mechanisms. Digital signatures and blockchain technology substitute for physical document verification, providing both higher reliability and automated processing that reduces system complexity
2Ease of operation
If electronic badges and documents are used for credential validation, then the ease of operation is improved, but the reliability deteriorates because badges can be lost or stolen and presented by imposters
Solution Approach 1:
The patent creates digital copies of credentials in the form of cryptographic assertions stored on blockchain networks. These digital assertions are much harder to forge or steal than physical badges, yet they provide the same ease of operation through mobile device presentation. The cryptographic signature ensures authenticity while the digital format maintains operational convenience
Solution Approach 2:
The patent changes the fundamental parameter of credential representation from physical objects (badges, documents) to cryptographic data structures. This parameter change transforms vulnerable physical credentials into secure digital assertions that can be easily verified through cryptographic validation, simultaneously improving both ease of operation and reliability
3Reliability
If proximity-based communications and cryptographic verification are implemented, then the reliability of identity validation is improved, but the device complexity and processing requirements increase
Solution Approach 1:
The patent performs preliminary cryptographic verification through proximity-based communication channels before final identity validation. By establishing secure channels and verifying assertions in advance through multiple trusted authorities, the system reduces the complexity of final verification steps, as much of the validation work is completed preliminarily through cryptographic proof
Data Source
AI summary
A method performed by a first computing device is disclosed. The method includes (a) establishing a proximity-based communications channel between the first computing device and a second computing device, one of the first device and the second device being a mobile device, (b) sending a request for authentication of identity of a remote entity from the first device to the second device, the remote entity being in possession of the second device, (c) receiving, at the first device, from the second device, an identity assertion that the remote entity is authentically identified by an identifier, the identity assertion's truth being conditional on a proximity-based condition, (d) verifying, at the first device, that the proximity-based condition is satisfied, and (e) in response to verifying, validating the identifier of the remote entity. An apparatus and computer program product for carrying out the method are also provided.


