Automated Credential Provisioning via Trusted Channels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in managing multiple accounts across different service providers due to the need for various security credentials, which can be cumbersome and insecure when trying to use a single username and password combination.

Innovation Solution

An automated system that designates a trusted device, such as a mobile device, to manage and reset security credentials for multiple accounts using trusted channels like email, phone calls, or text messages, employing temporary or device-specific authentication tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users manually manage security credentials for multiple accounts, then users can access all their accounts, but the complexity of managing numerous usernames and passwords increases significantly

Engineering Contradiction:
Improveability to access multiple accountsVSAvoidcomplexity of managing credentials
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a credential manager as an intermediary component that automatically handles the storage, retrieval, and management of security credentials. This mediator between the user and multiple accounts eliminates the need for users to manually track numerous usernames and passwords, thereby reducing credential management complexity while maintaining access to multiple accounts.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service through automated credential provisioning and management. The credential manager automatically retrieves credentials from service providers, stores them securely, and provides them when needed without requiring manual user intervention for each account access, thus reducing the burden of managing multiple credentials.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If users use a single username and password combination for multiple accounts, then ease of access improves, but security risks increase

Engineering Contradiction:
Improveease of account accessVSAvoidsecurity of credentials
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments security credentials by storing unique credentials for each account separately in the credential manager, rather than using a single universal password. This segmentation allows the system to maintain ease of access through automated credential retrieval while preserving security by ensuring each account has its own distinct credentials that are securely stored and managed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The credential manager acts as a secure intermediary that handles password retrieval automatically. Users interact only with the credential manager, which then provides the appropriate credentials for each account. This mediator approach maintains ease of operation for users while ensuring that security credentials remain protected and are not exposed or reused across multiple accounts.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If automated systems manage security credentials, then user burden is reduced, but the system requires trusted channels and device-specific tokens

Engineering Contradiction:
Improveuser burden in credential managementVSAvoidsystem requirements for trusted channels
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by establishing trusted communication channels and device-specific authentication tokens in advance. During initial setup, the credential manager configures secure communication pathways with service providers and generates device-specific tokens. This preliminary configuration reduces user burden during ongoing credential management while the system complexity is contained to the initial setup phase.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The automated credential management system performs self-service operations by automatically retrieving, storing, and providing credentials without user intervention. The system independently manages the complexity of trusted channels and device tokens, handling these technical requirements in the background while presenting a simplified interface to users, thereby reducing user burden without exposing them to system complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10057251B2Provisioning account credentials via a trusted channel
Publication Date: 2018.08.21 AMAZON TECH INC
  • US10057251B2 patent drawing
  • US10057251B2 patent drawing
  • US10057251B2 patent drawing

AI summary

Disclosed are various embodiments for provisioning account credentials via a trusted channel. An account configuration manager automatically determines a credential reset format that is associated with an account. The account configuration manager then automatically requests a security credential reset for the account using the credential reset format. A security credential communication is received via a trusted channel of communication that is linked to the account for reset purposes. The account configuration manager parses the security credential communication to determine a security credential for the account.