Client Device Reregistration Using User-Generated Recovery Codes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing process for client device reregistration in computing environments is burdensome for administrators, requiring supervised involvement to manage large numbers of devices, as credentials can be lost or compromised, necessitating frequent reauthentication.

Innovation Solution

An unsupervised client device reregistration process where a user device generates and validates a recovery code based on a recovery identifier and secret key, allowing the client device to automatically reauthenticate with the server device without administrator intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If supervised reregistration process is used, then security and control are maintained, but administrative workload increases significantly

Engineering Contradiction:
Improveauthentication securityVSAvoidadministrative efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements self-service reregistration where the client device autonomously generates and transmits recovery codes to the server device without requiring administrator intervention. The system automatically validates recovery codes and performs credential regeneration, eliminating the need for manual administrative oversight while maintaining security through automated verification mechanisms.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces a recovery code as an intermediary mechanism between the client device and server device. This recovery code serves as a temporary credential that enables the client device to prove its identity and request credential regeneration without direct administrator involvement. The server device validates this intermediary code to authorize the reregistration process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If frequent reregistration is required, then security is maintained, but time consumption increases

Engineering Contradiction:
ImprovesecurityVSAvoidreregistration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-generating and storing recovery identifiers and secret keys on the client device during initial registration. These pre-stored credentials enable rapid automated reregistration when needed, eliminating the need for time-consuming manual authentication processes. The system prepares recovery mechanisms in advance to reduce future time losses.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual mechanical authentication processes with automated electronic verification. Instead of requiring administrators to manually verify device identity and regenerate credentials, the system uses automated code generation, transmission, and validation mechanisms that perform the same function much faster with minimal human intervention.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If manual credential management is used, then control is maintained, but complexity of management increases

Engineering Contradiction:
ImprovecontrolVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The client device performs self-service credential management by automatically generating recovery codes, transmitting them to the server device, and receiving new credentials without administrator intervention. This eliminates the complex manual management process while maintaining control through automated verification mechanisms that ensure only authorized devices can regenerate credentials.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the parameters of credential management from manual static credentials to dynamic recovered credentials. The system transitions from fixed long-term credentials to time-limited recovery codes that automatically expire, enabling flexible credential regeneration without complex management. This parameter change simplifies the management process while maintaining security control.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11843596B2Reregistration of client device with server device using user device
Publication Date: 2023.12.12 MICRO FOCUS LLC
  • US11843596B2 patent drawing
  • US11843596B2 patent drawing
  • US11843596B2 patent drawing

AI summary

Subsequent to registration of a client device with a server device such that credentials by which the client device is authenticated are securely stored at the client device, the client device provides a user device and a server device a recovery identifier and a recovery secret key associated with the client device. Upon the credentials no longer being stored at the client device such that the client device has to be reregistered with the server device to store new credentials by which the client device is authenticated, the user device generates and provides a recovery code to the client device, which provides the recovery code to the server device. Upon validating the recovery code based on the recovery identifier and the recovery secret key, the server device reregisters the client device with the server device such that the new credentials are securely stored at the client device.