Personal-Service Identifier Decoupling for Token-Free Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods based on biometric data are vulnerable to false positives and negatives, and the management of identifiers is susceptible to computer attacks, data interception, and fraudulent reuse, with security relying on user-computation power and physical medium robustness.

Innovation Solution

A method involving the generation of non-reversible cryptographic functions to create unique digital identifiers, reference identifiers, and service identifiers, using a temporary random key, and applying these functions to ensure secure transactions without tokens, with a system architecture that integrates data security by design.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric data is used for authentication, then authentication capability is provided, but false positives and false negatives occur due to data variations and masking

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidbiometric data consistency
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the authentication process into two independent parts: a stable unique identifier (UI) that remains constant across sessions, and a volatile security matrix that changes each time. This segmentation allows the system to maintain reliable authentication through the stable UI while using the changing security matrix to prevent false positives and negatives by requiring active user participation in each authentication session.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a copy of the user identifier in the form of a security matrix that is generated fresh for each authentication session. This copy contains scrambled versions of the user identifier that must be unscrambled by the user during authentication, providing a reliable authentication mechanism that is not affected by biometric variations or masking since it relies on the user's knowledge of their identifier rather than their biometric characteristics.

Inventive Principle:
Principle #26Copying

2Reliability

If traditional identifier management is used, then user identification is achieved, but security is vulnerable to computer attacks, data interception, and fraudulent reuse

Engineering Contradiction:
Improveidentifier securityVSAvoidcomputer attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent transforms the static identifier system into a dynamic one where the security matrix changes with each authentication session. The security matrix is generated by scrambling the user identifier with a random element, creating a unique version for each session. This dynamic approach prevents fraudulent reuse and data interception attacks because the identifier presented to the server is different each time, making it impossible to store and reuse authenticator data.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a security matrix as an intermediary between the user identifier and the authentication process. This intermediary layer scrambles the user identifier before it is transmitted and stored, creating a protective barrier that prevents direct exposure of the unique identifier to computer attacks, data interception, and fraudulent reuse. The security matrix acts as a mediator that maintains security while allowing the system to function.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If biometric data storage is implemented, then authentication is enabled, but data privacy and security risks increase

Engineering Contradiction:
Improveauthentication convenienceVSAvoiddata privacy risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the biometric data requirement from the authentication process and replaces it with a knowledge-based approach using the unique identifier and security matrix. By taking out the need to store and process biometric data, the system eliminates the associated privacy risks and security vulnerabilities while maintaining authentication convenience through the use of the user's knowledge of their identifier and the generated security matrix.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses a disposable security matrix that is generated fresh for each authentication session and discarded afterward. This short-living object approach eliminates the need for permanent biometric data storage, as the security matrix is created temporarily during the authentication process and then discarded. This disposable approach reduces data privacy risks by ensuring that sensitive data is not stored long-term, while still providing convenient authentication through the use of the security matrix during the active session.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS12417451B2Authentication method secured by structural decoupling of personal and service identifiers
Publication Date: 2025.09.16 A3BC IP
  • US12417451B2 patent drawing
  • US12417451B2 patent drawing
  • US12417451B2 patent drawing

AI summary

A method for enabling secure transactions without the physical support of a security identifier and, in particular, without a token, consisting in recording on a first computer device B a unique digital identifier IDi associated with a unique user Ui, the profile IDi being associated with at least one service identifier IDsi associated with a service Si registered on a second computer device S which is different from the first computer device B, the service Si being accessible by the user Ui, and, during a transaction, acquiring the digital identifier IDi of a user Ui, transmitting it to the first computer device B for comparison with the registered ID identifiers and searching for and activating on the computer device S, at least one service associated with the identifier of the user Ui. The new user registration step includes: when a central computer device receives a profile Pi, executing a step for generating a temporary random master key X; and when the central computer device receives an identifier IDi, executing a step of searching for the pair (IDi, IDRx) on the first computer device B and applying the inverse function FR-1 to the identifier IDRx to determine the key X.