Verifiable Claim Binding for Privacy-Preserving Adaptive Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods face challenges in providing non-intrusive, privacy-preserving, and adaptive authentication solutions that dynamically adjust to the user's environment and location, while ensuring robust security without disclosing personal data, especially in transactions where location data may not be readily available.

Innovation Solution

The system employs non-intrusive privacy-preserving authenticators (NIPPA) that use a combination of non-intrusive sensors and explicit user authentication to calculate an assurance level, which is then communicated to the relying party without disclosing personal data, and adapts authentication methods based on environmental and behavioral data to ensure secure transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used, then security can be ensured, but user interaction and friction are required which reduces ease of operation

Engineering Contradiction:
Improveauthentication securityVSAvoiduser interaction requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs authentication automatically without requiring user interaction. The client device continuously monitors environmental sensors, behavioral data, and device state to self-determine authentication status, eliminating the need for manual login actions while maintaining security through adaptive assurance level calculations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary authentication assessments by continuously collecting environmental and behavioral data in the background before a transaction occurs. This preliminary action establishes an assurance level that can be quickly verified without requiring the user to perform authentication actions at the moment of transaction.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If personal data is disclosed for authentication, then authentication accuracy can be improved, but user privacy is compromised

Engineering Contradiction:
Improveauthentication accuracyVSAvoidpersonal data disclosure
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The system uses environmental sensors and behavioral data as intermediaries to assess authentication status without directly accessing or disclosing sensitive personal information. These intermediaries provide indirect evidence of user presence and device control, enabling accurate authentication while preserving privacy through proxy measurements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the parameters used for authentication from direct personal data (such as biometric templates or personal identifiers) to environmental and behavioral parameters (such as sensor readings, device usage patterns, and contextual information). This parameter transformation maintains authentication accuracy while eliminating the need to handle sensitive personal data.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If authentication adapts to environment and location, then security can be enhanced, but system complexity increases

Engineering Contradiction:
Improveadaptive securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses a unified authentication framework that handles multiple authentication scenarios (location-based, behavior-based, device-state-based) through a single adaptive assurance level calculation mechanism. This universal approach avoids the need for separate complex authentication systems for each scenario, reducing overall system complexity while maintaining adaptive security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements feedback loops where environmental sensors and behavioral data continuously inform the assurance level calculation, which in turn adjusts authentication requirements. This feedback mechanism enables automatic adaptation to changing conditions without requiring complex manual configuration or multiple independent decision systems.

Inventive Principle:
Principle #23Feedback

4Reliability

If continuous monitoring is performed for authentication, then security assurance is improved, but energy consumption increases

Engineering Contradiction:
Improveauthentication assurance levelVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs authentication monitoring periodically rather than continuously, assessing environmental and behavioral data at intervals sufficient to maintain security assurance while allowing the device to enter lower-power states between assessments. This periodic action reduces energy consumption while maintaining adequate authentication oversight.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system performs partial monitoring by selectively activating sensors and data collection based on contextual cues and risk assessment. Rather than continuously monitoring all parameters, the system activates monitoring only when authentication assurance needs to be updated or when environmental changes suggest potential security concerns, reducing energy consumption while maintaining security.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3738030B1System and method for binding verifiable claims
Publication Date: 2026.04.22 NOK NOK LABS INC
  • EP3738030B1 patent drawingFigure 1
  • EP3738030B1 patent drawingFigure 2
  • EP3738030B1 patent drawingFigure 3

AI summary

A system, apparatus, method, and machine readable medium are described for binding verifiable claims. For example, one embodiment of a system comprises: a client device; an authenticator of the client device to securely store authentication data including one or more verifiable claims received from one or more claim providers, each verifiable claim having attributes associated therewith; and claim/attribute processing logic to generate a first verifiable claim binding for a first verifiable claim issued by the claim provider; wherein the authenticator is to transmit a first signature assertion to a first relying party to authenticate with the first relying party, the first signature assertion including an attribute extension containing data associated with the first verifiable claim binding.