Shared-Device Passkey Authentication Without Hardware Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional authentication systems in shared computing environments face challenges in securely managing multiple user access without relying on dedicated hardware, leading to logistical complexities and increased operational costs.
Innovation Solution
A system utilizing passkeys and user identifiers, integrated through an authenticator application, that operates across various platforms, manages user passkeys centrally, and supports diverse identifier types like RFID/NFC cards, fingerprints, and QR codes, enabling secure, flexible, and scalable authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If external hardware authenticators are used for secure authentication, then security is improved, but device complexity and operational costs increase
Solution Approach 1:
The patent replaces physical hardware authenticators with a software-based authenticator application that runs on the shared computing device itself. The system uses software components including an authenticator application, authentication server, and integration with existing device sensors (fingerprint sensors, cameras, RFID readers) to provide hardware-free secure authentication. This substitution eliminates the need for separate hardware keys while maintaining security through software-based passkey management and biometric verification.
2Reliability
If dedicated hardware authenticators are provided for each user, then authentication security is improved, but logistical complexity and management burden increase
Solution Approach 1:
The patent merges the authentication functionality into a centralized authenticator application that serves all users on the shared device. Instead of distributing separate hardware authenticators to each user, the system combines multiple user credentials and authentication mechanisms within a single software application. The authentication server coordinates verification across all users, allowing administrators to manage all credentials centrally while users authenticate through a unified interface using their respective biometric or identifier-based credentials.
Solution Approach 2:
The authenticator application is designed as a universal solution that supports multiple authentication methods (fingerprint, facial recognition, RFID cards, passkeys) and serves multiple users on a single shared device. The system accommodates different authentication requirements for different users through configurable security settings, making a single piece of software perform the work of multiple hardware authenticators while reducing logistical complexity.
3Ease of operation
If traditional password-based authentication is used in shared environments, then ease of use is maintained, but security and personalization capabilities are insufficient
Solution Approach 1:
The patent changes the authentication parameter from knowledge-based (passwords) to possession-based and inherence-based factors (biometric data, fingerprint patterns, facial features, RFID identifiers). The system enrolls users with their unique biometric characteristics and uses these physiological parameters for authentication instead of memorized passwords. This parameter change maintains ease of use (users simply present their biometric trait) while dramatically improving security since biometric data cannot be easily stolen or guessed like passwords.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
Embodiments described herein provide systems and methods for secure and efficient user authentication across a variety of computing devices, such as desktops, laptops, smartphones, and tablets across operating systems such as Windows, MacOS, iOS, Android, and iPadOS. The system incorporates an authenticator application configured to communicate with internal or external user identifier scanners, such as RFID/NFC readers, fingerprint scanners, facial recognition cameras, and QR/Barcode scanners, using transport protocols like USB, BLE, or NFC. The authenticator application serves as a third-party passkey provider by interfacing with platform WebAuthn APIs, enabling WebAuthn-based authentication for native applications, browsers, and services, or alternatively as a browser extension, intercepting WebAuthn API calls directly within a browser environment. An authentication server, accessible over a network, verifies user identities by mapping unique identifiers to stored authenticators and requesting additional authentication factors as needed, such as a security PIN. Upon successful authentication, the server transmits passkeys and a session token to the authenticator application, enabling it to handle further authentication requests locally. The system supports advanced session management for shared device environments, allowing configurable passkey storage with options for one-time, time-based, or shift-based expiration, automatically clearing passkeys upon session completion. This design delivers a versatile, secure, and seamless authentication experience across diverse user environments.