Cloud Credential Management Service for Mobile NFC Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing credential management systems face limitations in efficiently managing and distributing credentials across various applications, particularly in access control, payment, and transit systems, where secure and flexible credential delivery is needed.
Innovation Solution
A cloud credential management service that generates and delivers virtual credentials to mobile devices, which can emulate contactless smartcards, using NFC technology for secure communication with reader devices, allowing for secure key management and credential distribution across different formats and applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If existing credential management systems are used, then credential distribution can be achieved, but the systems lack flexibility and security in delivering credentials across various applications
Solution Approach 1:
The patent introduces a credential management service as an intermediary component that sits between credential issuers and mobile devices. This service securely generates credentials, stores them in a protected environment, and delivers them to authorized devices through controlled interfaces. The intermediary architecture enables flexible credential distribution across multiple applications while maintaining centralized security controls and audit capabilities.
2Speed
If mobile devices store credentials locally, then access speed is improved, but security risks increase from local credential compromise
Solution Approach 1:
The patent segments the credential storage and management functionality into distinct components: a secure credential management service that maintains the master credential database, and mobile devices that store only derived credentials or credential tokens. This segmentation allows fast local authentication on mobile devices while the central service retains ultimate security control and can revoke or update credentials as needed.
Solution Approach 2:
The patent implements a nested credential structure where a master credential stored securely in the credential management service generates multiple derived credentials or tokens that are distributed to mobile devices. The nested hierarchy enables fast local verification using derived credentials while the master credential remains protected in the central service, providing both speed and security.
3Adaptability or versatility
If credentials are distributed across multiple devices, then system versatility is improved, but key management complexity increases
Solution Approach 1:
The patent implements self-service mechanisms where the credential management service automatically handles key generation, credential derivation, and distribution to multiple devices. The system autonomously manages the complexity of maintaining consistent security across multiple devices, performing key rotation, revocation, and synchronization without requiring manual intervention. This enables versatile multi-device credential distribution while keeping key management complexity centralized and automated.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enables secure, flexible, and efficient credential management, allowing mobile devices to function as secure access points for various applications, improving access control, payment, and transit systems by ensuring secure key distribution and credential matching, thus enhancing user authentication and authorization processes.
Implementation Method 1
mobile device having an NFC system, the NFC system comprising a processor and a memory device storing instructions which, when executed, cause the processor to perform the steps of the method
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
A server may communicate with a mobile device and/or a reader device via an Internet connection. The server may be configured to generate a credential and transmit the credential to the mobile device. The mobile device may use the credential in an access control system, a payment system, a transit system, a vending system, or the like.