Digital Credential Issuing System Using Public Storage Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital credential issuing systems face security risks due to the storage of master secret keys and interactive communication, which can lead to data breaches and denial of service attacks.

Innovation Solution

A digital credential issuing system that uses public storage as an intermediary between entities and the credential issuer, eliminating interactive communication and securing credentials through encryption, with a policy database determining issuance rules and the credential issuer generating encrypted credentials stored in public storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the credential issuer stores its master secret key to generate credentials, then the credential issuer can issue credentials to clients, but the security of the credential issuer is compromised due to potential data breaches

Engineering Contradiction:
Improvecredential issuance capabilityVSAvoidsecurity of credential issuer
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the master secret key from the credential issuer system and stores it externally in a secure key vault. The credential issuer can generate credentials without having direct access to or storing the master secret key, thereby maintaining issuance capability while eliminating the security risk of key storage within the issuer system.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a key vault as an intermediary component that securely stores the master secret key. The credential issuer interacts with the key vault through controlled interfaces to obtain necessary cryptographic materials for credential generation, without directly possessing or storing the master secret key, thus resolving the contradiction between operational capability and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If interactive communication is required for credential issuance, then security binding between request and response is achieved, but the credential issuer is exposed to denial of service attacks and data breaches

Engineering Contradiction:
Improvesecurity bindingVSAvoiddenial of service attacks and data breaches
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the interactive communication step from the credential issuance process. By using pre-configured policies and automated credential generation, the system eliminates the need for real-time interactive communication between the credential issuer and clients, thereby removing the attack surface for denial of service attacks while maintaining security through policy-based authorization.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements preliminary action by pre-configuring issuance policies and credential templates before actual credential requests. The system evaluates client requests against pre-established policies and generates credentials automatically without requiring interactive communication, thus achieving both security binding through policies and immunity to denial of service attacks.

Inventive Principle:
Principle #10Preliminary action

3Ease of manufacture

If the credential issuer maintains access to the master secret key for generating credentials, then credential generation is possible, but replacement or redundancy of the credential issuer becomes difficult

Engineering Contradiction:
Improvecredential generationVSAvoidreplacement and redundancy capability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent extracts the master secret key management function from the credential issuer and places it in a separate, secure key vault. This separation allows multiple credential issuers to be created and deployed without each one needing access to the master secret key, enabling easy replacement and redundancy while maintaining credential generation capability through the centralized key management system.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The key vault acts as an intermediary that provides controlled access to cryptographic materials needed for credential generation. Multiple credential issuers can be provisioned with appropriate permissions to the key vault, enabling seamless replacement and redundancy of individual issuers without affecting the overall system's ability to generate credentials securely.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11757857B2Digital credential issuing system and method
Publication Date: 2023.09.12 NTT RESEARCH INC
  • US11757857B2 patent drawing
  • US11757857B2 patent drawing
  • US11757857B2 patent drawing

AI summary

A digital credential issuing system and method use public storage and encryption to provide a more secure digital credential issuing process because there is no direct interaction between the credential issuer and an entity requesting a new credential. The new credential may be secured, such as by using encryption, so that the newly issued credential may be uploaded to the public storage and then decrypted and used by only the particular entity for which the new credential is intended.