Pseudonym Binding for Multi-Identity Cryptographic Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for online services face challenges in securely authenticating users across multiple services without correlating activities across different providers, leading to a need for a solution that allows secure, reusable authentication across various accounts without compromising privacy or security.

Innovation Solution

A method involving a security artifact, such as a cryptographic device or software module, is bound to a user account with a unique pseudonym for each service provider, enabling secure authentication by generating a pseudonym specific to the service provider, which is used to sign a nonce for validation, ensuring unlinkability across providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a user uses multiple authentication devices for different services, then security and identity assurance are improved, but device complexity and user burden increase

Engineering Contradiction:
Improveidentity assuranceVSAvoidnumber of authentication devices
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security artifact that can be used across multiple service providers. The artifact contains cryptographic capabilities that work with different services through a standardized interface, allowing one device to replace multiple service-specific authentication devices while maintaining security requirements

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If a security artifact is bound to multiple service providers, then authentication versatility is improved, but privacy protection deteriorates due to activity correlation

Engineering Contradiction:
Improveauthentication across servicesVSAvoidprivacy through activity correlation
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent segments the identification information by creating provider-specific pseudonyms that are generated and stored within the security artifact. Each service provider receives only its own pseudonym, not others', preventing correlation of activities across providers while maintaining the ability to authenticate with multiple services

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces pseudonyms as intermediary identifiers that mediate between the security artifact and service providers. These pseudonyms act as intermediaries that allow authentication without revealing the user's true identity or enabling cross-provider tracking

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If a unique identifier is used for the security artifact across all service providers, then device management is simplified, but security is worsened due to compromised unlinkability

Engineering Contradiction:
Improvedevice managementVSAvoidsecurity through unlinkability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by making the identifier property specific to each service provider context. The same physical artifact presents different pseudonymous identifiers to different providers, with each pseudonym being optimized for its specific provider relationship rather than using a single global identifier

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9264232B2Cryptographic device that binds an additional authentication factor to multiple identities
Publication Date: 2016.02.16 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9264232B2 patent drawing
  • US9264232B2 patent drawing
  • US9264232B2 patent drawing

AI summary

Binding a security artifact to a service provider. A method includes generating a pseudonym for a security artifact. The pseudonym is an identifier of the security artifact to the service provider that is unique to the service provider in that the pseudonym is not used to identify the security artifact to other service providers. Further, the pseudonym uniquely identifies the particular security artifact to the service provider even when a user has available a number of different security artifacts to authenticate to the same service provider to access a user account for the user. The method further includes providing the pseudonym for the security artifact to the service provider. The pseudonym for the security artifact is bound with a user account at the service provider for a user associated with the security artifact.