Trusted Third-Party Authentication Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems require users to reveal private data to authenticators, compromising privacy and increasing the risk of identity theft, as this data often passes through multiple hands before being used for verification.

Innovation Solution

The proposed method leverages trusted entities to authenticate users without exposing private data by encrypting and obfuscating the information, allowing only the user and the data possessor to access it in readable form, ensuring that no other party can read or use it, thus maintaining privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If private data is revealed to authenticators for verification purposes, then authentication reliability is improved, but privacy and security are compromised

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidprivacy compromise and identity theft risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a verification service as an intermediary that receives encrypted authentication data from the user, compares it with encrypted reference data from the data possessor, and returns verification results without ever decrypting or exposing the private data. This mediator architecture allows authentication to occur while keeping sensitive information isolated from all parties including the authenticator.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses encrypted copies of private data that can be compared without revealing the original data content. The verification service works with encrypted representations of authentication information, allowing verification operations to proceed on copies rather than the actual private data, thus maintaining security while enabling authentication.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If private data passes through multiple hands for verification, then authentication capability is improved, but the risk of data exposure and identity theft increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoiddata exposure risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The verification service acts as a secure intermediary that enables authentication capability across multiple parties (user, data possessor, authenticator) without requiring private data to pass through their hands. The service receives encrypted data from the user, compares it with encrypted reference data from the data possessor, and returns results to the authenticator, eliminating the need for data transfer through multiple vulnerable hands.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If more data items are used for authentication, then authentication reliability is improved, but user reluctance to supply private information increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiduser willingness to provide data
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system uses encrypted copies of authentication data that users can provide without compromising their privacy. Since the data remains encrypted throughout the process and is never exposed to the authenticator or verification service in readable form, users are more willing to supply the necessary data items for authentication while maintaining their privacy expectations.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS7676433B1Secure, confidential authentication with private data
Publication Date: 2010.03.09 RAF SOFTWARE TECH INC
  • US7676433B1 patent drawing
  • US7676433B1 patent drawing

AI summary

Risk of personal identity theft, especially in connection with on-line commerce, is mitigated by maintaining private data in a secure database maintained by a trusted third party verification service. To authenticate the identity of a user or customer, in one embodiment, a knowledge-based challenge is issued to the user, and the response is compared to stored data by the verification service. The verification service reports to the vendor, to authenticate the user identity, capability and or authorization for the proposed transaction without disclosing private data to the vendor.