Verifiable Claim Binding for Privacy-Preserving Adaptive Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods face challenges in providing non-intrusive, privacy-preserving, and adaptive authentication solutions that dynamically adjust to the user's environment and location, while ensuring robust security without disclosing personal data, especially in transactions where location data may not be readily available.
Innovation Solution
The system employs non-intrusive privacy-preserving authenticators (NIPPA) that use a combination of non-intrusive sensors and explicit user authentication to calculate an assurance level, which is then communicated to the relying party without disclosing personal data, and adapts authentication methods based on environmental and behavioral data to ensure secure transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used, then security can be ensured, but user interaction and friction are required which reduces ease of operation
Solution Approach 1:
The system performs authentication automatically without requiring user interaction. The client device continuously monitors environmental sensors, behavioral data, and device state to self-determine authentication status, eliminating the need for manual login actions while maintaining security through adaptive assurance level calculations.
Solution Approach 2:
The system performs preliminary authentication assessments by continuously collecting environmental and behavioral data in the background before a transaction occurs. This preliminary action establishes an assurance level that can be quickly verified without requiring the user to perform authentication actions at the moment of transaction.
2Measurement precision
If personal data is disclosed for authentication, then authentication accuracy can be improved, but user privacy is compromised
Solution Approach 1:
The system uses environmental sensors and behavioral data as intermediaries to assess authentication status without directly accessing or disclosing sensitive personal information. These intermediaries provide indirect evidence of user presence and device control, enabling accurate authentication while preserving privacy through proxy measurements.
Solution Approach 2:
The system changes the parameters used for authentication from direct personal data (such as biometric templates or personal identifiers) to environmental and behavioral parameters (such as sensor readings, device usage patterns, and contextual information). This parameter transformation maintains authentication accuracy while eliminating the need to handle sensitive personal data.
3Reliability
If authentication adapts to environment and location, then security can be enhanced, but system complexity increases
Solution Approach 1:
The system uses a unified authentication framework that handles multiple authentication scenarios (location-based, behavior-based, device-state-based) through a single adaptive assurance level calculation mechanism. This universal approach avoids the need for separate complex authentication systems for each scenario, reducing overall system complexity while maintaining adaptive security.
Solution Approach 2:
The system implements feedback loops where environmental sensors and behavioral data continuously inform the assurance level calculation, which in turn adjusts authentication requirements. This feedback mechanism enables automatic adaptation to changing conditions without requiring complex manual configuration or multiple independent decision systems.
4Reliability
If continuous monitoring is performed for authentication, then security assurance is improved, but energy consumption increases
Solution Approach 1:
The system performs authentication monitoring periodically rather than continuously, assessing environmental and behavioral data at intervals sufficient to maintain security assurance while allowing the device to enter lower-power states between assessments. This periodic action reduces energy consumption while maintaining adequate authentication oversight.
Solution Approach 2:
The system performs partial monitoring by selectively activating sensors and data collection based on contextual cues and risk assessment. Rather than continuously monitoring all parameters, the system activates monitoring only when authentication assurance needs to be updated or when environmental changes suggest potential security concerns, reducing energy consumption while maintaining security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system, apparatus, method, and machine readable medium are described for binding verifiable claims. For example, one embodiment of a system comprises: a client device; an authenticator of the client device to securely store authentication data including one or more verifiable claims received from one or more claim providers, each verifiable claim having attributes associated therewith; and claim/attribute processing logic to generate a first verifiable claim binding for a first verifiable claim issued by the claim provider; wherein the authenticator is to transmit a first signature assertion to a first relying party to authenticate with the first relying party, the first signature assertion including an attribute extension containing data associated with the first verifiable claim binding.