Personal-Service Identifier Decoupling for Token-Free Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods based on biometric data are vulnerable to false positives and negatives, and the management of identifiers is susceptible to computer attacks, data interception, and fraudulent reuse, with security relying on user-computation power and physical medium robustness.
Innovation Solution
A method involving the generation of non-reversible cryptographic functions to create unique digital identifiers, reference identifiers, and service identifiers, using a temporary random key, and applying these functions to ensure secure transactions without tokens, with a system architecture that integrates data security by design.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric data is used for authentication, then authentication capability is provided, but false positives and false negatives occur due to data variations and masking
Solution Approach 1:
The patent segments the authentication process into two independent parts: a stable unique identifier (UI) that remains constant across sessions, and a volatile security matrix that changes each time. This segmentation allows the system to maintain reliable authentication through the stable UI while using the changing security matrix to prevent false positives and negatives by requiring active user participation in each authentication session.
Solution Approach 2:
The patent creates a copy of the user identifier in the form of a security matrix that is generated fresh for each authentication session. This copy contains scrambled versions of the user identifier that must be unscrambled by the user during authentication, providing a reliable authentication mechanism that is not affected by biometric variations or masking since it relies on the user's knowledge of their identifier rather than their biometric characteristics.
2Reliability
If traditional identifier management is used, then user identification is achieved, but security is vulnerable to computer attacks, data interception, and fraudulent reuse
Solution Approach 1:
The patent transforms the static identifier system into a dynamic one where the security matrix changes with each authentication session. The security matrix is generated by scrambling the user identifier with a random element, creating a unique version for each session. This dynamic approach prevents fraudulent reuse and data interception attacks because the identifier presented to the server is different each time, making it impossible to store and reuse authenticator data.
Solution Approach 2:
The patent introduces a security matrix as an intermediary between the user identifier and the authentication process. This intermediary layer scrambles the user identifier before it is transmitted and stored, creating a protective barrier that prevents direct exposure of the unique identifier to computer attacks, data interception, and fraudulent reuse. The security matrix acts as a mediator that maintains security while allowing the system to function.
3Ease of operation
If biometric data storage is implemented, then authentication is enabled, but data privacy and security risks increase
Solution Approach 1:
The patent extracts the biometric data requirement from the authentication process and replaces it with a knowledge-based approach using the unique identifier and security matrix. By taking out the need to store and process biometric data, the system eliminates the associated privacy risks and security vulnerabilities while maintaining authentication convenience through the use of the user's knowledge of their identifier and the generated security matrix.
Solution Approach 2:
The patent uses a disposable security matrix that is generated fresh for each authentication session and discarded afterward. This short-living object approach eliminates the need for permanent biometric data storage, as the security matrix is created temporarily during the authentication process and then discarded. This disposable approach reduces data privacy risks by ensuring that sensitive data is not stored long-term, while still providing convenient authentication through the use of the security matrix during the active session.
Data Source
AI summary
A method for enabling secure transactions without the physical support of a security identifier and, in particular, without a token, consisting in recording on a first computer device B a unique digital identifier IDi associated with a unique user Ui, the profile IDi being associated with at least one service identifier IDsi associated with a service Si registered on a second computer device S which is different from the first computer device B, the service Si being accessible by the user Ui, and, during a transaction, acquiring the digital identifier IDi of a user Ui, transmitting it to the first computer device B for comparison with the registered ID identifiers and searching for and activating on the computer device S, at least one service associated with the identifier of the user Ui. The new user registration step includes: when a central computer device receives a profile Pi, executing a step for generating a temporary random master key X; and when the central computer device receives an identifier IDi, executing a step of searching for the pair (IDi, IDRx) on the first computer device B and applying the inverse function FR-1 to the identifier IDRx to determine the key X.


