Application Credential Generation Using Master Key
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing credential systems for wireless devices face challenges in providing strong authentication for applications accessing proprietary data servers, as they often require multiple passwords or rely on manufacturing processes that do not scale for large numbers of applications or downloaded applications.
Innovation Solution
A credential system that generates application credentials using a master credential and application identifier, allowing applications to authenticate with data servers without the need for special passwords, by using a credential server to verify and match application and server credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate passwords are issued to each device user for authentication, then strong authentication is achieved, but user responsibility and overhead for application developers increase significantly
Solution Approach 1:
The system enables self-service authentication where the device automatically generates and manages credentials using the master credential and application identifier. The credential system operates autonomously without requiring users to manually create, distribute, or manage passwords, eliminating user responsibility while maintaining strong authentication through automated credential verification.
2Reliability
If separate passwords are distributed to each device user, then authentication is possible, but the requirement to create, distribute, and maintain passwords for every application used by every user creates significant overhead
Solution Approach 1:
The master credential serves as a universal authentication foundation that can generate credentials for any number of applications and devices. Instead of creating separate password management systems for each application, the credential system provides a single multi-functional solution where one master credential can authenticate multiple applications across multiple devices through automated credential generation and verification.
3Reliability
If a separate key is provisioned into every device at manufacturing, then authentication is achieved, but the system does not scale to large numbers of applications or downloaded applications
Solution Approach 1:
The system transitions from static pre-provisioned keys to dynamic credential generation. The master credential stored in read-only memory remains static, but it dynamically generates unique credentials for each application based on the application identifier. This dynamic approach allows the system to adapt to any number of applications including downloaded applications without requiring re-manufacturing or re-provisioning of devices.
4Ease of operation
If application credentials are generated using a master credential and application identifier, then strong authentication without multiple passwords is achieved, but a secure credential system must be implemented
Solution Approach 1:
The credential system acts as an intermediary between the device and the data server. Instead of requiring complex credential management at both ends, the credential system receives the application identifier, generates the corresponding credential using the master credential, and provides it to the application. This intermediary simplifies the authentication process by centralizing credential management while maintaining security through automated verification.
Data Source
AI summary
Methods and apparatus for providing an application credential for an application running on a device. In one embodiment, a method provides an application credential to an application running on a device, wherein the application credential is used by the application to authenticate to a data server. The method comprises receiving a request to generate the application credential, wherein the request includes an application identifier. The method also comprises generating the application credential using the application identifier and a master credential associated with the device.


