Passwordless Authentication via Trusted Device Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current password-based authentication systems are insecure, as they can be easily compromised, leading to unauthorized access and phishing attacks, and passwordless authentication methods are not truly passwordless since they still rely on initial password registration.
Innovation Solution
A passwordless user account system that uses a network of trusted devices for authentication, where users prove physical presence through gestures or biometrics, generating device credentials without the need for passwords, ensuring secure access and preventing remote hacking.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If password-based authentication is used, then account registration is simple, but security is compromised and accounts are vulnerable to attacks
Solution Approach 1:
The patent extracts the password element entirely from the authentication system. Instead of using passwords for registration and authentication, the system uses device credentials stored in trusted devices. The registration process takes out the password requirement and replaces it with device-based authentication, where the trusted device proves the user's identity without exposing any password-like secret.
Solution Approach 2:
The patent introduces a trusted device as an intermediary between the user and the authentication system. This device acts as a mediator that stores device credentials and performs authentication operations. The intermediary device enables secure authentication without requiring the user to directly manage passwords, thus improving security while maintaining simplicity for end users.
2Reliability
If biometric authentication is used, then passwordless access is enabled on device, but initial password registration is still required
Solution Approach 1:
The patent inverts the traditional authentication flow. Instead of requiring password registration first and then optionally enabling biometric authentication, the system performs biometric/device-based authentication first during registration. This inversion eliminates the need for password registration entirely, making the system truly passwordless from the outset while maintaining ease of operation.
3Ease of operation
If same password is used across multiple accounts, then convenience is improved, but security risk increases significantly
Solution Approach 1:
The patent segments the authentication credentials so that each trusted device has its own unique device credential. Instead of using a single password across multiple accounts and devices, the system creates distinct cryptographic credentials for each device. This segmentation ensures that compromise of one device's credential does not affect other devices or accounts, eliminating the security risk of password reuse while maintaining convenience through multiple trusted devices.
Data Source
AI summary
Provided is passwordless user registration process in which a user initially registers a device or a network of trusted devices rather than submitting a password. Thus, example embodiments are directed to a truly passwordless user account across all devices. In one example, a method may include receiving a registration request of an unregistered user from an authentication device, the registration request comprising a user identifier and a device credential obtained by the authentication device, performing a passwordless registration of the unregistered user with an application, wherein the performing comprises registering the unregistered user as a passwordless user with passwordless access to the application and registering the authentication device as a first trusted device of the passwordless user, and transmitting a notification to the authentication device indicating successful passwordless registration.


