Non-Intrusive Privacy-Preserving Authenticator Assurance Level

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods face challenges in providing non-intrusive and privacy-preserving solutions, especially in environments where explicit user interaction is not feasible or desirable, and where reliable location data may not be available.

Innovation Solution

The implementation of a non-intrusive privacy-preserving authenticator (NIPPA) that uses a combination of non-intrusive authentication mechanisms, such as location and behavioral data, to determine an assurance level that the legitimate user is in possession of the device, without disclosing personal or environmental data to the relying party.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If non-intrusive authentication mechanisms (location, behavioral data) are used to determine assurance level, then authentication security is improved and user privacy is protected, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is divided into separate modules: location detection module, behavioral data detection module, and assurance level determination module. Each module independently collects and processes specific types of data, then the results are combined to compute the overall assurance level. This segmentation allows the system to achieve comprehensive authentication security while maintaining manageable complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary processing layer that collects raw data from multiple sources (location, device identifiers, network information), processes this data through cryptographic operations, and outputs a synthesized assurance level. This intermediary layer abstracts the complexity of data processing from the authentication decision-making process, enabling secure multi-factor authentication without exposing the underlying complexity to the relying party.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If continuous measurement of assurance level is implemented, then authentication security is enhanced without adding friction, but energy consumption increases

Engineering Contradiction:
Improveauthentication securityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Instead of continuous real-time monitoring, the system implements periodic sampling of location and behavioral data at defined intervals. The assurance level is updated periodically rather than continuously, reducing energy consumption while maintaining adequate security. The periodic action allows the system to balance security requirements with energy efficiency by updating authentication status only when necessary rather than in constant real-time mode.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The authentication system leverages data and processing capabilities that already exist on the device (location services, sensor data, network stack) without requiring additional dedicated hardware or intensive external processing. The device uses its own existing resources to perform authentication functions, minimizing the energy overhead of adding new authentication mechanisms while maintaining strong security through creative reuse of available device capabilities.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250039169A1System and method for pre-registration of FIDO authenticators
Publication Date: 2025.01.30 NOK NOK LABS INC
  • US20250039169A1 patent drawing
  • US20250039169A1 patent drawing
  • US20250039169A1 patent drawing

AI summary

A system, apparatus, method, and machine-readable medium are described for personalizing and pre-registering an authenticator. For example, one embodiment of a method comprising: confirming an identity of a user by a relying party using a first identity verification technique responsive to the user performing a first transaction with the relying party; generating or collecting initial user verification reference data upon verification of the identity of the user through the first identity verification technique; requesting personalization of an authenticator to be provided to the user; receiving credential registration data of the authenticator after personalization; receiving a transaction request from the user that requires user authentication; and authenticating the user based on the authenticator and the credential registration data of the authenticator using a second identity verification technique.