Credential Management Application Using Trust Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing credential management systems require users to remember and authenticate with multiple organizations separately, leading to complexity and inefficiency in accessing various credentials and associated resources.

Innovation Solution

A credential management application that allows users to log in with authentication information from one credential-issuing organization, enabling access to credentials and resources from other trusted organizations, using trust data and user-defined restrictions to manage access permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users authenticate with each credential-issuing organization separately, then security and authorization accuracy are improved, but operation complexity and time consumption increase

Engineering Contradiction:
Improveauthorization accuracyVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a credential management system as an intermediary between users and multiple credential-issuing organizations. This system stores credential data and authentication information centrally, allowing users to authenticate once with the management system and then access credentials from multiple organizations without separate authentication processes, thus reducing operation complexity while maintaining authorization accuracy through the intermediary's verification mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent combines multiple authentication processes into a single unified authentication through the credential management system. By merging the storage and verification of credentials from multiple organizations into one centralized system, users only need to authenticate once, and the system handles the coordination with multiple organizations, thereby reducing authentication complexity while maintaining security

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If users store credentials from multiple organizations, then access versatility is improved, but security risk and management complexity increase

Engineering Contradiction:
Improvecredential access versatilityVSAvoidcredential management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The credential management system provides universal access to credentials from multiple different organizations through a single platform. The system is designed to handle various types of credentials (digital certificates, API keys, authentication tokens) from diverse organizations, allowing users to access all credentials through one unified interface, thus improving versatility while the system automatically manages the complexity of storing and organizing these diverse credentials

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If trust data is shared between organizations, then access efficiency is improved, but security vulnerability and trust management complexity increase

Engineering Contradiction:
Improveaccess efficiencyVSAvoidsecurity trustworthiness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the credential management system continuously verifies and updates trust relationships between organizations. When credentials are accessed, the system checks current trust data and authorization status, providing feedback loops that ensure security policies are maintained. This allows efficient access while maintaining security through continuous verification and dynamic trust management

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10769262B1Enabling use of credentials
Publication Date: 2020.09.08 STRATEGY INC
  • US10769262B1 patent drawing
  • US10769262B1 patent drawing
  • US10769262B1 patent drawing

AI summary

A system enables use of credentials, including determining that a user has been authorized by a first credential-issuing organization and enabling the user to use a first credential issued by the first credential-issuing organization based on the determination that the user has been authorized by the first credential-issuing organization. Trust data indicating whether the user should be enabled to use a second credential issued by a second credential-issuing organization as a result of the user having been authorized by the first credential-issuing organization is accessed. A determination is made that the accessed trust data indicates that the user should be enabled to use the second credential issued by the second credential-issuing organization as a result of the user having been authorized by the first credential-issuing organization, and the user is enabled to use the second credential.