OpenID Passkey Registration for Biometric Mobile Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing OpenID security standards fail to provide secure and efficient passkey authentication for mobile devices, lacking support for biometric authentication and multi-factor authentication, and expose vulnerabilities due to proprietary APIs and email-based verification.
Innovation Solution
The system extends OpenID standards by implementing a secure end-to-end algorithm for passkey registration and authentication, using a 'create' mode parameter and a signature parameter to protect against forgeries, supporting mobile devices through a new request header, and integrating with native mobile operating systems to manage passkeys natively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing OpenID security standards are used for passkey authentication, then implementation simplicity is maintained, but security vulnerabilities increase due to lack of support for biometric authentication and multi-factor authentication
Solution Approach 1:
The patent segments the authentication system into distinct components: the OpenID provider handles traditional authentication, while a new passkey registration server handles passkey-specific operations including biometric verification and multi-factor authentication. This segmentation allows each component to specialize in its function, improving security without requiring the entire OpenID system to be redesigned.
Solution Approach 2:
The patent introduces a passkey registration server as an intermediary between the OpenID provider and the client device. This intermediary coordinates the passkey registration process, managing the interaction between the OpenID standard and passkey technology, thereby enabling enhanced security features while maintaining compatibility with existing OpenID infrastructure.
2Reliability
If proprietary APIs are used for passkey implementation, then specific functionality is achieved, but network vulnerabilities increase due to email-based verification and lack of standardization
Solution Approach 1:
The patent creates a universal passkey registration system that works across multiple platforms and devices. By implementing a standardized protocol that supports various authentication methods (biometric, multi-factor) and device types (mobile, desktop), the system achieves broad compatibility while maintaining security through standardized verification processes rather than proprietary implementations.
3Reliability
If current OpenID standard is used for mobile implementations, then web view support is provided, but passkey authentication support is limited due to restriction to embedded mobile browsers
Solution Approach 1:
The patent extends the OpenID standard into a new dimension by adding passkey-specific registration and authentication flows that operate alongside the traditional OpenID process. This allows passkey authentication to function in mobile environments through native app integration rather than being confined to web views, thereby expanding platform support while maintaining security.
4Reliability
If traditional email verification is used for passkey registration, then implementation simplicity is maintained, but security is reduced due to susceptibility to phishing and email compromise
Solution Approach 1:
The patent changes the verification parameter from email-based OTP to biometric verification and multi-factor authentication. By requiring the user to verify their identity through biometric data (fingerprint, facial recognition) or multiple authentication factors during passkey registration, the system significantly enhances security while maintaining a user-friendly process through the use of device-native authentication mechanisms.
Data Source
AI summary
Security registration and authentication systems and methods are disclosed herein for extending OpenID security standards for registration of OpenID client devices for passkey authentication. A client device comprises client frontend application (app). A registration and authentication server comprises a client backend app for receiving an authorization request of the client device comprising a prompt parameter, and implementing one of: (a) a secure registration algorithm if the prompt parameter defines a create value; or (b) an authentication algorithm if the prompt parameter does not define the create value. The security registration and authentication systems and methods provide an authentication token to the client device, the authentication token authenticating the client device to initiate a secure session with a secure resource on a computer network.


