Authentication Credential Transfer Between Client Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing authentication systems face inefficiencies when users need to enroll new client devices, as the process is often manual, time-consuming, and error-prone, requiring human intervention and multiple steps due to securely stored authentication credentials.

Innovation Solution

An authentication system that facilitates the transfer of enrollment between client devices by receiving authorization from the enrolled device using authentication credentials, updating authentication information on the new device, and verifying user presence, thereby simplifying the enrollment process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication credentials are securely stored on client devices using TPM or cryptographic storage techniques, then security reliability is improved, but device enrollment complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice enrollment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication system as an intermediary that facilitates enrollment transfers between devices. The system receives enrollment transfer requests from non-enrolled devices, verifies authorization using the enrolled device's credentials, and processes the transfer of authentication information without requiring direct manual intervention between devices. This intermediary approach simplifies the enrollment process while maintaining secure credential storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements self-service enrollment transfer where the enrolled device automatically provides authorization for credential transfer to a new device. The system uses the enrolled device's authentication credentials to automatically generate and transmit enrollment information to the new device, eliminating the need for manual unenrollment and re-enrollment steps that would otherwise be required.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual unenrollment and re-enrollment steps are performed, then credential security is maintained, but user time consumption increases

Engineering Contradiction:
Improvecredential securityVSAvoiduser time consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-establishing the enrolled device's authorization credentials in the authentication system before the transfer process. When a new device requests enrollment transfer, the system already has the necessary authorized credentials stored, allowing it to immediately process the transfer without requiring time-consuming manual verification or re-authentication steps.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent maintains continuous useful action by keeping the enrolled device's authentication credentials actively authorized in the system throughout the transfer process. Rather than requiring credential revocation and reissuance, the system continuously uses the existing authorized credentials to facilitate the seamless transfer of enrollment information to the new device, eliminating interruptions and time losses.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If administrator intervention is required for enrollment, then system control is maintained, but operational efficiency decreases

Engineering Contradiction:
Improvesystem controlVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements self-service enrollment transfer where the system automatically processes enrollment transfers based on authorization requests from enrolled devices. The authentication system automatically verifies credentials, processes the transfer of authentication information, and updates device enrollment status without requiring administrator intervention, thereby maintaining system control while significantly improving operational efficiency.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where the authentication system automatically receives and processes enrollment transfer requests, verifies authorization using the enrolled device's credentials, and confirms the transfer completion. This automated feedback loop eliminates the need for administrator review and approval, allowing the system to self-manage enrollment transfers while maintaining security control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11943366B2Efficient transfer of authentication credentials between client devices
Publication Date: 2024.03.26 OKTA INC
  • US11943366B2 patent drawing
  • US11943366B2 patent drawing
  • US11943366B2 patent drawing

AI summary

An authentication system facilitates a transfer of enrollment in authentication services between client devices. The authentication system enrolls a client device in authentication services to enable the client device to be used for authenticating requests to access one or more services. As part of enrolling the client device, the authentication system receives authentication enrollment information for the client device that is associated with one or more authentication credentials securely stored on the client device (e.g., a multi-factor authentication (MFA) certificate). The authentication system facilitates one or more processes for transferring the enrollment from an enrolled client device to a non-enrolled client device that limit the number and complexity of actions performed by the user. In particular, the authentication system facilitates transfer of enrollment based on receiving enrollment transfer requests authorized by the enrolled client device using one or more authentication credentials associated with the enrollment of the enrolled client device.