Inspiration

Secret credentials are indispensable for identity assurance, whereas text-only passwords are hard to manage. Why not consider Non-Text secret credentials?

What it does

Our identity authentication solution named Expanded Password System enables people to make use of their episodic image memory.

How we built it

The system is built to enable the user to register a set of any numbers of images of their choice either by permutation or combination as credentials and embed them onto a matrix of images made of meaningless decoy images

Our solution turned out to work with Open ID without friction.

Challenges we ran into

However solid the theory is, the solution would be vulnerable to attacks when it is poorly implemented. A key was the appropriate use of a hash module of SHA family.

It was also a challenge to get technology people to listen to us about the merit of making use of our own autobiographic/episodic memory. These people are generally not familiar with such psychological concepts.

Accomplishments that we're proud of

Adoption by demanding clients such as Japan's Ground Self-Defense Force (Army) besides the use cases in consumer and corporation areas.

Also, selection as a finalist by Financial Data and Technology Association for ‘Summit and Awards 2019’ and adoption by AFCEA for ‘2020 Solution Review Problem Sets’.

What we learned

Our solution can and must be made available to global citizens.

We also learned that, for global citizens to enjoy a safer identity assurance, we need to debunk wide-spread misperceptions such as “indispensable passwords be removed altogether” and “passwords be displaced by password-dependent biometrics”

What's next for Digital Identity for Global Citizens

Global operations

Built With

  • cloud
  • cryptography
Share this project:

Updates

posted an update

< Loss of Cryptocurrency's Digital Wallet >

I have heard that a sizeable chunk of cryptocurrencies is evaporating by the loss of digital wallets.

Let me talk how we could be of help in this aspect..

We would only need to provide people with a software module with which to re-generate both the password and the private key for the digital wallet on-the-fly from their episodic image memories as outlined in this article - “Account Recovery with Expanded Password System” https://www.linkedin.com/pulse/account-recovery-expanded-password-system-hitoshi-kokumai/

Log in or sign up for Devpost to join the conversation.

posted an update

‘Authenticators’ and ‘Deployment of Authenticators’

It appears that there are not a few security professionals who wrongly mix up the layer of ‘authenticators’ with that of ‘deployment of authenticators’, talking as though the former and the latter were competing each other, for example, ‘Multi-Factor Authentication is better than a password’ and ‘ID federation is better than a password’.

The password is an ‘authenticator’. So are the token and biometrics. Whereas MFA and ID federation like FIDO and Open ID are ‘deployment of the authenticators’

Expanded Password System is to be found on the layer of 'authenticator', while the likes of Open ID and FIDO are all to be found on the upper layer of 'deployment of authenticators' and, as such, the likes of Open ID and FIDO could naturally be our down-stream partners.

Log in or sign up for Devpost to join the conversation.

posted an update

In view of the ever rampant Covid-19, let me refer to the theme of Digital Identity in Post-Pandemic Era.

Very probably, global populations will be far more dependent on Digital Identity in the Post-Covid19 era that our life will be far less dependent on geographical move of people - fewer face-to-face meetings, less commute, fewer travels and far more dependent on telemedicine, telework and many other tele-something, while threats of Big Brothers by rogue governments, greedy corporations and crime syndicates will be yet greater than ever.

The likes of Self-Sovereign Identity, expected to play a critical role in the highly complex situations, would require not just the distributed ledger technology but the most reliable identity authentication if it is to be truly valid and sustainable.

Our responsibility of providing ‘hard-to-forget’, ‘hard-to-break’ and ‘stress-proof’ authentication will be really heavy.

Log in or sign up for Devpost to join the conversation.

posted an update

Yet another report on the drive to destroy security by removing passwords

How naïve security professionals can be? An answer is found in this report -“Passwords begone: GitHub will ban them next year for authenticating Git operations” https://www.theregister.com/2020/12/17/github_bans_passwords/

Aren’t they actually offering a ‘solution’ that can be compared to the ATM that rejects PIN (numbers-only password) and dispenses cash upon the presentation of only a bank/credit card?

Ref: “Bizarre Theory of Password-less Authentication” https://www.linkedin.com/posts/hitoshikokumai_is-the-future-of-cybersecurity-passwordless-activity-6740797972310843392-H85v

Log in or sign up for Devpost to join the conversation.

posted an update

Yet another report on the password predicament

“We're not saying this is how SolarWinds was backdoored, but its FTP password 'leaked on GitHub in plaintext'” https://www.theregister.com/2020/12/16/solarwinds_github_password/ It says "their update server was accessible with the password 'solarwinds123'”.

Every time these absurd incidents are reported, we are told to listen to security professionals who love to lecture us to manage the text-only passwords that we are incapable of managing.

How long do we have to keep hearing them preaching “We would be safe if we do what we are unable to do”?

I wonder why those people are not keen to look at the merits of making use of non-text secret credentials besides the text passwords.

Ref: “On #BigIdeas2021” https://www.linkedin.com/posts/hitoshikokumai_after-police-raid-on-covid-19-whistleblower-activity-6744799100195209216-P0AQ

Log in or sign up for Devpost to join the conversation.

posted an update

Let me mention a bit more about “wide-spread misperceptions” referred to in “What we learned”. Below are my latest writings as for “indispensable passwords be removed altogether” and “passwords be displaced by password-dependent biometrics”.

Bizarre Theory of Password-less Authentication https://www.linkedin.com/posts/hitoshikokumai_is-the-future-of-cybersecurity-passwordless-activity-6740797972310843392-H85v

Why are we so persistent in the efforts to bust the falsehood of biometrics? https://www.linkedin.com/posts/hitoshikokumai_market-ready-for-biometric-payment-cards-activity-6740104039905665024-u4P8

Log in or sign up for Devpost to join the conversation.

posted an update

The aim of our enterprise is to make Expanded Password System (EPS) solutions readily available to all the global citizens: rich and poor, young and old, healthy and disabled, literate and illiterate, in peace and in disasters.

We expect EPS to stay with us over many generations until humans discover something other than the 'digital identity' for our safe and orderly societal life. We look for the people who share such a long-term view and support us as such.

Expanded Password System invented in 2000, we launched the business operations in 2001 under the name of Mnemonic Security, Inc, which was the world’s first company to provide the software products that offer ‘Hard-to-Forget’, ‘Hard-to-Break’ and ‘Panic-Proof’ digital identity authentication. The business progressed successfully with US$1m commercial adoptions over the first several years.

We started, however, to feel the painful headwind from around 2008 because people got carried away by the hype of wrongly-used biometrics, particularly overwhelming in Japan, even though the versatile practicability of our software was demonstrated by the 5-year use by 140, 000 online shoppers. After struggling in vain for several years, we chose to get out of Japan.

We have successfully made a tangible progress since then. The solid theory of our EPS proposition is made clear by OASIS recognition as a standard candidate, publishing by Taylor & Francis, selection as a finalist by Financial Data and Technology Association for ‘Summit and Awards 2019’ in Edinburgh and adoption by AFCEA for ‘2020 Solution Review Problem Sets’. We are steadily getting recognized as Pioneer and Thought Leader in this domain.

As for the use cases, we are now able to also refer to the 6-year use by 1,200 employees for a corporate network and the trouble-free defense use by army soldiers in the field from 2013 till now with the users increasing 10-fold and set to increase further, which were both achieved in very adverse circumstances of biometrics-dominated Japan.

We came to set up a company in UK as our global headquarters in August 2020. We named it 'Mnemonic Identity Solutions Limited' with the mission of globally promoting 'identity assurance by our own volition and memory' for 'secure digital identity in post-pandemic cyberspace'.

Log in or sign up for Devpost to join the conversation.