Remote Device Enrollment via Identity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identity management systems face vulnerabilities and friction in onboarding new or replacement devices, particularly due to the need for manual verification and stringent protocols that hinder IT teams and users, and are susceptible to attacks like phishing and spearfishing.
Innovation Solution
A system for remote device enrollment that utilizes a trusted execution environment (TEE) and identity management services to securely onboard devices through a process involving initial user verification, device verification, and communication sessions for attestation, allowing for efficient verification of device and user possession without physical presence.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual verification and stringent protocols are implemented in identity management systems, then security against unauthorized access is improved, but operational friction and complexity for IT teams and users increases
Solution Approach 1:
The system enables users to perform self-service device enrollment by initiating verification requests from their devices and receiving automated verification through communication sessions, eliminating the need for manual IT team intervention in the verification process while maintaining security protocols
Solution Approach 2:
The identity management system acts as an intermediary between users and resources, automatically managing verification processes through communication sessions and device verification values, reducing operational friction while maintaining stringent security protocols
2Reliability
If device enrollment requirements are enforced in identity management systems, then prevention of unauthorized device access is improved, but onboarding efficiency for new or replacement devices deteriorates
Solution Approach 1:
The system performs preliminary device verification by obtaining device verification values and establishing communication sessions before granting access, ensuring unauthorized access prevention is built into the enrollment process rather than added as a post-hoc constraint
Solution Approach 2:
Users can initiate device enrollment and verification requests from their devices themselves, eliminating the need for manual IT team processing and significantly improving onboarding efficiency while maintaining enrollment requirements
3Measurement precision
If physical presence verification is required for device onboarding, then identity verification accuracy is improved, but time consumption and operational complexity increases
Solution Approach 1:
The system replaces physical presence verification with electronic communication sessions between devices, using audio and video communications to verify user identity remotely, maintaining verification accuracy while eliminating the need for physical presence and associated time losses
Data Source
AI summary
Provided are systems, processes, and methods for identity management, such as the verification of an identity of a user of device for securely onboarding a device remotely and other use cases. A user may access a webpage or obtain a native application on their device with which the user engages to prove their identity to an identity verifier delegated to attest to the identity of the user. A communication session is established between the user and the identity verifier via their respective devices. If the identity verifier attests to the asserted identity of the user, the device of the user may be issued a deep link, code, or other for the establishment or exchange of credential information with an identity management system. Embodiments of such systems may also be used for other instances of identity or device verification.


