Secure Credential Transfer Using Device Trust Verification Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for transferring user credentials to a new device do not adequately verify the security of the device, requiring cumbersome user interactions and potential security risks.

Innovation Solution

A method and system that verifies both user and device identity using an authentication server, establishing a secure channel through token exchange and mutual identity verification before credential transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional login methods are used for new device setup, then user credentials can be transferred, but security verification of the device is insufficient and user interaction is cumbersome

Engineering Contradiction:
Improvedevice security verificationVSAvoiduser interaction complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary device verification by checking the device identifier against the authentication server before initiating credential transfer. This preliminary security check ensures the device is trustworthy before any user interaction or credential exposure occurs, resolving the contradiction by establishing security upfront rather than requiring complex ongoing verification during the transfer process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication server acts as an intermediary between the user's trusted device and the new device. It verifies the new device's identifier and issues authentication tokens without requiring the user to manually input credentials or navigate complex security procedures. This intermediary mechanism automates security verification while simplifying user interaction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual login steps are required for new device setup, then credentials can be entered, but the process is time-consuming and security risks increase

Engineering Contradiction:
Improvecredential transfer securityVSAvoidsetup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service credential transfer by automatically verifying the new device through its identifier against the authentication server. The device itself participates in the verification process by providing its identifier, and the system automatically establishes security credentials without requiring manual user input. This eliminates time-consuming manual login steps while maintaining security through automated verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The authentication server performs preliminary verification of the device identifier and pre-establishes security tokens before credential transfer begins. This preliminary authentication action ensures security is already in place before any credentials are transmitted, eliminating the need for time-consuming manual security checks during the transfer process.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If device security verification is implemented, then credential transfer becomes more secure, but the authentication process becomes more complex

Engineering Contradiction:
Improvedevice trust verificationVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts the device identifier from the new device and uses it as the primary verification element against the authentication server. By isolating and verifying only this essential identifier rather than requiring comprehensive device analysis or multiple verification layers, the system achieves reliable device trust verification while keeping the authentication process simple and straightforward.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4005177B1Method and system for authenticating a secure credential transfer to a device
Publication Date: 2026.02.18 GOOGLE LLC
  • EP4005177B1 patent drawingFigure 1
  • EP4005177B1 patent drawingFigure 2
  • EP4005177B1 patent drawingFigure 3

AI summary

A method for authenticating a secure credential transfer to a device (130) includes verifying user identity (306) and device identity (308). In particular, the method includes verifying user identity by requesting (412, 414) and receiving (310, 416) a user identification input at a first client device ( 120) and verifying device identity of a second client device (130) by (i) determining (408) a security status of the second client device (130) from hardware of the second client device (130), (ii) invoking (418, 420) an identifier related to the security status of the second client device (130) to an authentication server (110), and (iii) obtaining (424) certification from the authentication server (110) for the second client device (130) based on the invoked identifier. After verifying the user identity and the device identity, the method includes establishing (312, 448) a secure channel between the first client device (120) and the second client device (130) for the secure credential transfer using one or more tokens (436, 444, 446) generated by the authentication server (110).