Passwordless Authentication via Trusted Device Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current password-based authentication systems are insecure, as they can be easily compromised, leading to unauthorized access and phishing attacks, and passwordless authentication methods are not truly passwordless since they still rely on initial password registration.

Innovation Solution

A passwordless user account system that uses a network of trusted devices for authentication, where users prove physical presence through gestures or biometrics, generating device credentials without the need for passwords, ensuring secure access and preventing remote hacking.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If password-based authentication is used, then account registration is simple, but security is compromised and accounts are vulnerable to attacks

Engineering Contradiction:
Improveaccount securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the password element entirely from the authentication system. Instead of using passwords for registration and authentication, the system uses device credentials stored in trusted devices. The registration process takes out the password requirement and replaces it with device-based authentication, where the trusted device proves the user's identity without exposing any password-like secret.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a trusted device as an intermediary between the user and the authentication system. This device acts as a mediator that stores device credentials and performs authentication operations. The intermediary device enables secure authentication without requiring the user to directly manage passwords, thus improving security while maintaining simplicity for end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If biometric authentication is used, then passwordless access is enabled on device, but initial password registration is still required

Engineering Contradiction:
Improveauthentication securityVSAvoidregistration process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent inverts the traditional authentication flow. Instead of requiring password registration first and then optionally enabling biometric authentication, the system performs biometric/device-based authentication first during registration. This inversion eliminates the need for password registration entirely, making the system truly passwordless from the outset while maintaining ease of operation.

Inventive Principle:
Principle #13The other way round (Inversion)

3Ease of operation

If same password is used across multiple accounts, then convenience is improved, but security risk increases significantly

Engineering Contradiction:
Improvelogin convenienceVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authentication credentials so that each trusted device has its own unique device credential. Instead of using a single password across multiple accounts and devices, the system creates distinct cryptographic credentials for each device. This segmentation ensures that compromise of one device's credential does not affect other devices or accounts, eliminating the security risk of password reuse while maintaining convenience through multiple trusted devices.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11409861B2Passwordless authentication
Publication Date: 2022.08.09 BOLIMOVSKY HERBERT
  • US11409861B2 patent drawing
  • US11409861B2 patent drawing
  • US11409861B2 patent drawing

AI summary

Provided is passwordless user registration process in which a user initially registers a device or a network of trusted devices rather than submitting a password. Thus, example embodiments are directed to a truly passwordless user account across all devices. In one example, a method may include receiving a registration request of an unregistered user from an authentication device, the registration request comprising a user identifier and a device credential obtained by the authentication device, performing a passwordless registration of the unregistered user with an application, wherein the performing comprises registering the unregistered user as a passwordless user with passwordless access to the application and registering the authentication device as a first trusted device of the passwordless user, and transmitting a notification to the authentication device indicating successful passwordless registration.