Credential Gateway for Interoperable Secure Credential Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing physical access control systems require users to be in close proximity to access devices, introducing latency and frustration, while mobile devices with diverse proprietary credential technologies complicate digital identity delivery and storage due to lack of standardization.

Innovation Solution

A credential gateway system that coordinates the exchange of digital credentials across different secure resource types, managing storage on client devices using trusted execution environments (TEE) or secure elements (eSE), encrypting credentials, and ensuring interoperability across various devices and manufacturers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If physical access control systems are used, then users can access secure resources, but users must be in close proximity to access devices which introduces latency and frustration

Engineering Contradiction:
Improveaccess convenienceVSAvoidaccess latency
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent replaces physical proximity-based access control with wireless digital credential verification. Mobile devices communicate with access control systems via wireless protocols (NFC, Bluetooth, Wi-Fi), eliminating the need for physical proximity and manual card insertion, thereby reducing access latency and improving convenience

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates digital copies of physical credentials (access cards, keys) that can be stored and transmitted electronically. These digital credential copies enable remote verification and faster access compared to physical systems, while maintaining security through cryptographic verification

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If mobile devices with diverse proprietary credential technologies are used, then digital identity delivery is enabled, but lack of standardization complicates storage and interoperability

Engineering Contradiction:
Improvedevice compatibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal credential gateway that can store and manage multiple types of digital credentials (access control, payment, identification) across different device platforms. The gateway uses standardized protocols to interface with various mobile devices regardless of their native credential technologies, enabling one system to serve multiple functions and device types

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The credential gateway acts as an intermediary layer between diverse mobile devices and secure resource access systems. It translates between different credential formats and protocols, managing the complexity centrally rather than requiring each device to support all credential types natively, thus reducing overall system complexity while maintaining versatility

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12395486B2Credential gateway storing different credentials on different secure storage types
Publication Date: 2025.08.19 ASSA ABLOY AB
  • US12395486B2 patent drawing
  • US12395486B2 patent drawing
  • US12395486B2 patent drawing

AI summary

Methods and systems are provided for performing operations comprising: receiving, by a credential gateway from a client device, a request to obtain a digital credential for accessing a secure resource, the credential gateway being configured to coordinate an exchange of digital credentials associated with different secure resource types with a plurality of client devices; communicating the request to a server associated with the secure resource; receiving, by the credential gateway from the server associated with the secure resource, a data object that includes the digital credential; selecting, by the credential gateway, based on the data object, a security protocol from a plurality of security protocols; and providing, by the credential gateway, the digital credential to the client device in accordance with the selected security protocol.