Cloud Credential Management Service for Mobile NFC Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing credential management systems face limitations in efficiently managing and distributing credentials across various applications, particularly in access control, payment, and transit systems, where secure and flexible credential delivery is needed.

Innovation Solution

A cloud credential management service that generates and delivers virtual credentials to mobile devices, which can emulate contactless smartcards, using NFC technology for secure communication with reader devices, allowing for secure key management and credential distribution across different formats and applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If existing credential management systems are used, then credential distribution can be achieved, but the systems lack flexibility and security in delivering credentials across various applications

Engineering Contradiction:
Improvecredential delivery flexibilityVSAvoidcredential security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a credential management service as an intermediary component that sits between credential issuers and mobile devices. This service securely generates credentials, stores them in a protected environment, and delivers them to authorized devices through controlled interfaces. The intermediary architecture enables flexible credential distribution across multiple applications while maintaining centralized security controls and audit capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If mobile devices store credentials locally, then access speed is improved, but security risks increase from local credential compromise

Engineering Contradiction:
Improveaccess speedVSAvoidcredential compromise risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent segments the credential storage and management functionality into distinct components: a secure credential management service that maintains the master credential database, and mobile devices that store only derived credentials or credential tokens. This segmentation allows fast local authentication on mobile devices while the central service retains ultimate security control and can revoke or update credentials as needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a nested credential structure where a master credential stored securely in the credential management service generates multiple derived credentials or tokens that are distributed to mobile devices. The nested hierarchy enables fast local verification using derived credentials while the master credential remains protected in the central service, providing both speed and security.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Adaptability or versatility

If credentials are distributed across multiple devices, then system versatility is improved, but key management complexity increases

Engineering Contradiction:
Improvemulti-device credential distributionVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the credential management service automatically handles key generation, credential derivation, and distribution to multiple devices. The system autonomously manages the complexity of maintaining consistent security across multiple devices, performing key rotation, revocation, and synchronization without requiring manual intervention. This enables versatile multi-device credential distribution while keeping key management complexity centralized and automated.

Inventive Principle:
Principle #25Self-service

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enables secure, flexible, and efficient credential management, allowing mobile devices to function as secure access points for various applications, improving access control, payment, and transit systems by ensuring secure key distribution and credential matching, thus enhancing user authentication and authorization processes.

Implementation Method 1

mobile device having an NFC system, the NFC system comprising a processor and a memory device storing instructions which, when executed, cause the processor to perform the steps of the method

Methodology Applied
Scientific EffectNear Field Communication (NFC): Electromagnetic Induction

Data Source

PatentEP2815535B1Credential management system
Publication Date: 2018.11.14 SCHLAGE LOCK CO LLC
  • EP2815535B1 patent drawingFigure 1~2
  • EP2815535B1 patent drawingFigure 3~4
  • EP2815535B1 patent drawingFigure 5

AI summary

A server may communicate with a mobile device and/or a reader device via an Internet connection. The server may be configured to generate a credential and transmit the credential to the mobile device. The mobile device may use the credential in an access control system, a payment system, a transit system, a vending system, or the like.