Chain-of-Trust Authentication for Multi-Device Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Providing multiple user devices with access to resources is cumbersome and insecure, as they often lack appropriate interfaces for credentials and storing credentials across devices exposes them to hacking and unauthorized use.

Innovation Solution

A system and method for authenticating and authorizing user devices using a resource provider computer that identifies and transmits authentication requests between devices, and a processing network computer that maintains associations between credentials and user devices, enabling secure and efficient access to resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If credentials are stored in each user device, then access to resources is enabled, but security is compromised due to hacking and unauthorized use

Engineering Contradiction:
Improveaccess to resourcesVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the credential storage function from individual user devices and centralizes it in a credential service provider system. The credential service provider securely stores credentials and manages distribution to authorized devices, eliminating the need for each device to store sensitive credentials locally. This resolves the contradiction by enabling resource access while maintaining security through centralized credential management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a credential service provider as an intermediary between users and resources. This intermediary manages credential distribution, verification, and revocation, allowing multiple devices to access resources without each device needing to store credentials. The intermediary ensures security by controlling credential access and enabling remote revocation if compromise is detected.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If credentials are manually entered into each device, then access is enabled, but user burden increases significantly

Engineering Contradiction:
Improveaccess to resourcesVSAvoiduser effort
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent implements self-service credential management where the credential service provider automatically handles credential distribution, verification, and device authorization. Users simply need to authenticate once with the credential service provider, which then automatically manages credentials across all their devices. This eliminates the need for manual credential entry into each device, significantly reducing user burden and time loss.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal credential management system that works across multiple devices and resource types. The credential service provider provides a single interface for managing credentials that automatically applies to all user devices, whether mobile phones, computers, or IoT devices. This multi-functional approach allows one authentication action to enable access across all devices, eliminating repetitive manual entry.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If interfaces for credential entry are added to all devices, then access is enabled, but device complexity increases

Engineering Contradiction:
Improveaccess to resourcesVSAvoidinterface requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the credential management functionality from individual devices and relocates it to the credential service provider. Devices only need minimal communication capabilities to interact with the credential service provider, eliminating the need for complex credential entry interfaces, secure storage mechanisms, and credential management software in each device. This resolves the contradiction by enabling access while maintaining device simplicity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The credential service provider acts as an intermediary that handles all complex credential management operations. Devices simply communicate authentication requests and responses with the credential service provider, which manages the complex tasks of credential verification, device authorization, and secure credential distribution. This intermediary approach enables access without requiring complex interfaces or functionality in individual devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12456116B2System and method utilizing chain of trust
Publication Date: 2025.10.28 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US12456116B2 patent drawing
  • US12456116B2 patent drawing
  • US12456116B2 patent drawing

AI summary

Embodiments of the invention are directed to systems and methods for authenticating a user device using an authenticating device that has previously been associated with a user and/or a credential. The user may initiate a transaction at the user device. An authenticating device associated with the transaction may be sent an authentication request corresponding to the user device. The user may indicate whether or not the user device is authenticated utilizing the authenticating device. If the user device is authenticated, the transaction may proceed. If the user device is not authenticated the transaction may be rejected.