Credential Management System for Secure Virtual Key Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack an efficient method for users to share virtual keys associated with credentials securely and conveniently, without relying on email or social networks, while ensuring access constraints are enforced.

Innovation Solution

A system that allows users to share virtual keys through representations like QR codes, acoustic codes, or alphanumeric codes, with constraints such as time and location, using a credential management system that verifies access rights and enforces sharing permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users share virtual keys through traditional methods (email or social networks), then key sharing is achieved, but security is compromised and user convenience is reduced

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a credential management system as an intermediary between key owners and key recipients. This system generates secure representations of keys (QR codes, acoustic codes, alphanumeric codes) and manages the sharing process, eliminating the need for users to rely on email or social networks while maintaining security through controlled key distribution and verification mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates secure copies of virtual keys in the form of representations (QR codes, acoustic codes, alphanumeric codes) that can be safely transmitted and shared. These representations are generated by the credential management system and can be distributed through various channels without compromising the security of the original key, as the system verifies and manages access to these copies

Inventive Principle:
Principle #26Copying

2Ease of operation

If virtual keys are shared without constraints, then user convenience is improved, but security and access control are compromised

Engineering Contradiction:
Improveuser convenienceVSAvoidaccess control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic constraints on key sharing, allowing the credential management system to enforce time-based restrictions, location-based restrictions, and usage count limitations. These constraints are applied automatically during the key sharing process, enabling convenient key distribution while maintaining security through programmable access control policies that adapt to different scenarios

Inventive Principle:
Principle #15Dynamics

3Reliability

If a credential management system with constraint enforcement is implemented, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs a universal credential management system that handles multiple key sharing scenarios through a single platform. The system generates various types of key representations (QR codes, acoustic codes, alphanumeric codes) and enforces multiple constraint types (time, location, usage count) through unified mechanisms, reducing overall system complexity by consolidating functionality rather than creating separate systems for each scenario

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10275956B1Sharing keys
Publication Date: 2019.04.30 STRATEGY INC
  • US10275956B1 patent drawing
  • US10275956B1 patent drawing
  • US10275956B1 patent drawing

AI summary

The subject matter described in this specification includes a computer-readable medium storing instructions that cause one or more processors to perform various operations including receiving, from a first client device associated with a user account of a first user, a request for sharing a key. The key is associated with the user account of the first user, and permits access to a resource. The operations include generating, at a server, one or more representations of the key, transmitting the representations of the key to the first client device, and receiving, from a second client device associated with a user account of a second user, a request to access the key. The request to access the key is derived from one of the one or more representations of the key. The operations further include communicating, to the second client device, a message indicating whether access to the key has been granted.