Mutual Authentication via Location-Verified Token Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication technologies fail to mutually authenticate individuals during in-person meetings, lacking symmetric authentication methods that combine digital and physical verification, and often require trusted third parties or multiple communication steps.

Innovation Solution

A system that uses device identifiers and visual tokens, along with Generative Adversarial Networks (GANs), to enable mutual authentication by exchanging communications identifiers and tokens between users' devices upon verification of their location, employing both digital and physical authentication methods to confirm identities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing authentication technologies are used for in-person meetings, then authentication can be performed, but mutual authentication between individuals cannot be achieved and trusted third parties are required

Engineering Contradiction:
Improveauthentication confidenceVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the trusted third party from the authentication process by enabling direct peer-to-peer authentication between users. Each user's device independently verifies the other's identity using exchanged authentication data, eliminating the need for centralized authentication servers or intermediaries while maintaining high authentication confidence.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication process is segmented into distinct phases: pre-meeting setup where users generate and exchange authentication data, and in-meeting verification where devices independently validate each other's identities. This segmentation allows complex authentication to be broken down into manageable steps that can be performed without continuous third-party involvement.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple communication steps are used for authentication, then verification can be performed, but the authentication process becomes complex and time-consuming

Engineering Contradiction:
Improveverification accuracyVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication data is generated and exchanged before the meeting occurs during a setup phase. This preliminary action allows the actual in-meeting authentication to be rapid, as devices simply need to verify pre-exchanged data rather than performing multiple communication rounds during the meeting itself.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If digital authentication methods are used alone, then authentication can be performed remotely, but physical presence verification cannot be confirmed

Engineering Contradiction:
Improveauthentication convenienceVSAvoidphysical presence verification
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent merges digital authentication methods (device identifiers, encrypted data exchange) with physical verification mechanisms (location services, in-person token exchange). This combination allows users to authenticate conveniently through their devices while simultaneously confirming physical presence at the meeting location, addressing both convenience and verification precision requirements.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20220191027A1Mutual multi-factor authentication technology
Publication Date: 2022.06.16 KYNDRYL INC
  • US20220191027A1 patent drawing
  • US20220191027A1 patent drawing
  • US20220191027A1 patent drawing

AI summary

Computer software that stores information relating to a planned in-person meeting between a first user and a second user. The information includes a meeting time, a meeting location, and, for each of the first user and the second user: (i) a communications identifier associated with a device of the respective user, and (ii) a token identified by the respective user for the meeting. The computer software, in response to receiving an indication that the device of the first user is located at the meeting location at the meeting time, sends, to the device of the first user: (i) the communications identifier associated with the device of the second user, and (ii) the token identified by the second user for the meeting.