Chain-of-Trust Authentication for Multi-Device Resource Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Providing multiple user devices with access to resources is cumbersome and insecure, as they often lack appropriate interfaces for credentials and storing credentials across devices exposes them to hacking and unauthorized use.
Innovation Solution
A system and method for authenticating and authorizing user devices using a resource provider computer that identifies and transmits authentication requests between devices, and a processing network computer that maintains associations between credentials and user devices, enabling secure and efficient access to resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If credentials are stored in each user device, then access to resources is enabled, but security is compromised due to hacking and unauthorized use
Solution Approach 1:
The patent extracts the credential storage function from individual user devices and centralizes it in a credential service provider system. The credential service provider securely stores credentials and manages distribution to authorized devices, eliminating the need for each device to store sensitive credentials locally. This resolves the contradiction by enabling resource access while maintaining security through centralized credential management.
Solution Approach 2:
The patent introduces a credential service provider as an intermediary between users and resources. This intermediary manages credential distribution, verification, and revocation, allowing multiple devices to access resources without each device needing to store credentials. The intermediary ensures security by controlling credential access and enabling remote revocation if compromise is detected.
2Ease of operation
If credentials are manually entered into each device, then access is enabled, but user burden increases significantly
Solution Approach 1:
The patent implements self-service credential management where the credential service provider automatically handles credential distribution, verification, and device authorization. Users simply need to authenticate once with the credential service provider, which then automatically manages credentials across all their devices. This eliminates the need for manual credential entry into each device, significantly reducing user burden and time loss.
Solution Approach 2:
The patent creates a universal credential management system that works across multiple devices and resource types. The credential service provider provides a single interface for managing credentials that automatically applies to all user devices, whether mobile phones, computers, or IoT devices. This multi-functional approach allows one authentication action to enable access across all devices, eliminating repetitive manual entry.
3Ease of operation
If interfaces for credential entry are added to all devices, then access is enabled, but device complexity increases
Solution Approach 1:
The patent extracts the credential management functionality from individual devices and relocates it to the credential service provider. Devices only need minimal communication capabilities to interact with the credential service provider, eliminating the need for complex credential entry interfaces, secure storage mechanisms, and credential management software in each device. This resolves the contradiction by enabling access while maintaining device simplicity.
Solution Approach 2:
The credential service provider acts as an intermediary that handles all complex credential management operations. Devices simply communicate authentication requests and responses with the credential service provider, which manages the complex tasks of credential verification, device authorization, and secure credential distribution. This intermediary approach enables access without requiring complex interfaces or functionality in individual devices.
Data Source
AI summary
Embodiments of the invention are directed to systems and methods for authenticating a user device using an authenticating device that has previously been associated with a user and/or a credential. The user may initiate a transaction at the user device. An authenticating device associated with the transaction may be sent an authentication request corresponding to the user device. The user may indicate whether or not the user device is authenticated utilizing the authenticating device. If the user device is authenticated, the transaction may proceed. If the user device is not authenticated the transaction may be rejected.


