Trusted Third-Party Authentication Mediator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems require users to reveal private data to authenticators, compromising privacy and increasing the risk of identity theft, as this data often passes through multiple hands before being used for verification.
Innovation Solution
The proposed method leverages trusted entities to authenticate users without exposing private data by encrypting and obfuscating the information, allowing only the user and the data possessor to access it in readable form, ensuring that no other party can read or use it, thus maintaining privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If private data is revealed to authenticators for verification purposes, then authentication reliability is improved, but privacy and security are compromised
Solution Approach 1:
The patent introduces a verification service as an intermediary that receives encrypted authentication data from the user, compares it with encrypted reference data from the data possessor, and returns verification results without ever decrypting or exposing the private data. This mediator architecture allows authentication to occur while keeping sensitive information isolated from all parties including the authenticator.
Solution Approach 2:
The patent uses encrypted copies of private data that can be compared without revealing the original data content. The verification service works with encrypted representations of authentication information, allowing verification operations to proceed on copies rather than the actual private data, thus maintaining security while enabling authentication.
2Adaptability or versatility
If private data passes through multiple hands for verification, then authentication capability is improved, but the risk of data exposure and identity theft increases
Solution Approach 1:
The verification service acts as a secure intermediary that enables authentication capability across multiple parties (user, data possessor, authenticator) without requiring private data to pass through their hands. The service receives encrypted data from the user, compares it with encrypted reference data from the data possessor, and returns results to the authenticator, eliminating the need for data transfer through multiple vulnerable hands.
3Reliability
If more data items are used for authentication, then authentication reliability is improved, but user reluctance to supply private information increases
Solution Approach 1:
The system uses encrypted copies of authentication data that users can provide without compromising their privacy. Since the data remains encrypted throughout the process and is never exposed to the authenticator or verification service in readable form, users are more willing to supply the necessary data items for authentication while maintaining their privacy expectations.
Data Source
AI summary
Risk of personal identity theft, especially in connection with on-line commerce, is mitigated by maintaining private data in a secure database maintained by a trusted third party verification service. To authenticate the identity of a user or customer, in one embodiment, a knowledge-based challenge is issued to the user, and the response is compared to stored data by the verification service. The verification service reports to the vendor, to authenticate the user identity, capability and or authorization for the proposed transaction without disclosing private data to the vendor.

