Cryptographic Credential Distribution via Controller Gateway

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for remote connectivity over public communication networks face challenges in managing cryptographic data distribution and revocation, particularly for enterprises with multiple applications requiring different cryptographic credentials, leading to complexity and burden in security management.

Innovation Solution

A method for distributing cryptographic credentials from an enterprise to a user's remote device, where a domain administrator configures a controller and gateway to specify whether credentials are on-demand or pre-stored, with the controller or gateway handling credential provision, ensuring secure and efficient credential management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic credentials are distributed to each user for every application, then authentication security is improved, but administrative burden and complexity increase

Engineering Contradiction:
Improveauthentication securityVSAvoidadministrative burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal credential store that can provide different cryptographic credentials for different applications through a single distributed credential. The credential store acts as a multi-functional component that adapts to various application requirements, eliminating the need for separate credential distribution for each application while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a credential store as an intermediary component between the user and multiple applications. This mediator manages and provides appropriate cryptographic credentials to different applications without requiring direct credential distribution from the enterprise to each user, thereby reducing administrative burden while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If VPN is used for remote connectivity, then network security is improved, but system complexity and vulnerability to malware increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication function from the complex VPN infrastructure and implements it as a standalone credential verification system. This allows remote users to connect without requiring full VPN complexity, reducing system complexity while maintaining security through dedicated credential-based authentication.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If cryptographic certificates are required for strong authentication, then authentication security is improved, but certificate management burden increases

Engineering Contradiction:
Improveauthentication securityVSAvoidcertificate management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple cryptographic credentials and their management into a single distributed credential store. This consolidation allows the system to manage multiple certificates and keys through one unified interface, reducing the certificate management burden while maintaining strong authentication security across different applications.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10652230B2Generation and distribution of secure or cryptographic material
Publication Date: 2020.05.12 ROUTE1
  • US10652230B2 patent drawing
  • US10652230B2 patent drawing
  • US10652230B2 patent drawing

AI summary

A user having remote device wants to access an application that requires that the user possess a user application cryptographic credential. If the application needs to verify the identity of the user, the user's remote device performs a cryptographic operation using the user application cryptographic credentials, and sends the result to the application. A configuration for securely distributing the user application cryptographic credentials includes at least one gateway located at an enterprise that is under the control of an enterprise administrator, and a controller that is not located at the enterprise but can be configured by the enterprise administrator to cooperate with the at least one gateway.