Remote Device Enrollment via Identity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity management systems face vulnerabilities and friction in onboarding new or replacement devices, particularly due to the need for manual verification and stringent protocols that hinder IT teams and users, and are susceptible to attacks like phishing and spearfishing.

Innovation Solution

A system for remote device enrollment that utilizes a trusted execution environment (TEE) and identity management services to securely onboard devices through a process involving initial user verification, device verification, and communication sessions for attestation, allowing for efficient verification of device and user possession without physical presence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual verification and stringent protocols are implemented in identity management systems, then security against unauthorized access is improved, but operational friction and complexity for IT teams and users increases

Engineering Contradiction:
ImprovesecurityVSAvoidoperational friction
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables users to perform self-service device enrollment by initiating verification requests from their devices and receiving automated verification through communication sessions, eliminating the need for manual IT team intervention in the verification process while maintaining security protocols

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The identity management system acts as an intermediary between users and resources, automatically managing verification processes through communication sessions and device verification values, reducing operational friction while maintaining stringent security protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If device enrollment requirements are enforced in identity management systems, then prevention of unauthorized device access is improved, but onboarding efficiency for new or replacement devices deteriorates

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidonboarding efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary device verification by obtaining device verification values and establishing communication sessions before granting access, ensuring unauthorized access prevention is built into the enrollment process rather than added as a post-hoc constraint

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Users can initiate device enrollment and verification requests from their devices themselves, eliminating the need for manual IT team processing and significantly improving onboarding efficiency while maintaining enrollment requirements

Inventive Principle:
Principle #25Self-service

3Measurement precision

If physical presence verification is required for device onboarding, then identity verification accuracy is improved, but time consumption and operational complexity increases

Engineering Contradiction:
Improveidentity verification accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system replaces physical presence verification with electronic communication sessions between devices, using audio and video communications to verify user identity remotely, maintaining verification accuracy while eliminating the need for physical presence and associated time losses

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250023874A1Device enrollment identity verification
Publication Date: 2025.01.16 HYPR CORP
  • US20250023874A1 patent drawing
  • US20250023874A1 patent drawing
  • US20250023874A1 patent drawing

AI summary

Provided are systems, processes, and methods for identity management, such as the verification of an identity of a user of device for securely onboarding a device remotely and other use cases. A user may access a webpage or obtain a native application on their device with which the user engages to prove their identity to an identity verifier delegated to attest to the identity of the user. A communication session is established between the user and the identity verifier via their respective devices. If the identity verifier attests to the asserted identity of the user, the device of the user may be issued a deep link, code, or other for the establishment or exchange of credential information with an identity management system. Embodiments of such systems may also be used for other instances of identity or device verification.