Cryptographic Indirection for Selective Digital Credential Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securely sharing digital credentials among multiple entities are inadequate, particularly in scenarios requiring selective and revocable access, as they often involve full disclosure or lack support for many-to-many relationships and do not address the need for transparent and secure credential sharing in network access scenarios.

Innovation Solution

A method and system that utilize cryptographic indirection techniques to securely and selectively share digital credentials among entities by generating a shared secret based on a common secret and entity-specific strings, allowing controlled access and revocation of credentials, incorporating algorithms like hashing, concatenation, and symmetric cryptography for protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is encoded using various techniques to prevent unauthorized access, then security is improved, but the ability to securely share information with another entity becomes more difficult

Engineering Contradiction:
ImprovesecurityVSAvoidability to share information
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a credential sharing mechanism that acts as an intermediary between the data owner and the accessing entity. Instead of directly sharing encoded data or credentials, the system uses a credential store with protection means that mediates access control. The sharing entity can selectively grant access to specific credentials without disclosing the actual credential values, thus maintaining security while enabling controlled information sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the Microsoft encrypting file system is used to allow an entity to specify which registered entities may access encoded information, then file sharing security is improved, but the mechanism does not support multiple entities sharing a common workspace with selective encoding of discrete files

Engineering Contradiction:
Improvefile sharing securityVSAvoidsupport for many-to-many relationships
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal credential sharing framework that can handle multiple sharing scenarios including one-to-many, many-to-many, and selective credential sharing. The credential store with protection means serves multiple functions: storing credentials, managing access rights, enabling selective sharing, and supporting revocation. This multi-functional system replaces the limited file-level sharing mechanism with a versatile credential-based access control system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If full disclosure of a user's credentials is provided to network administrators for assisting users, then access assistance capability is improved, but security is compromised as unnecessary credentials are disclosed

Engineering Contradiction:
Improveaccess assistance capabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements local quality by enabling selective credential sharing where the data owner can specify exactly which credentials to share and with which entities. Instead of full disclosure, the protection means allows granular control over credential access. Network administrators can receive only the specific credentials needed to assist a user, while other credentials remain protected. This localized access control maintains security while providing necessary assistance capabilities.

Inventive Principle:
Principle #3Local quality

4Adaptability or versatility

If partial portion of credentials is disclosed for security purposes, then selective sharing capability is improved, but the disclosure remains undesirable from a security perspective

Engineering Contradiction:
Improveselective sharing capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a credential sharing mechanism as an intermediary that enables selective sharing without direct credential disclosure. The protection means acts as a secure gateway that allows the sharing entity to control which credentials are accessible to which entities, without the actual credential values being exposed. This intermediary mechanism provides selective sharing capability while maintaining security by never disclosing the actual credential data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10178078B1Secure digital credential sharing arrangement
Publication Date: 2019.01.08 ASSA ABLOY AB
  • US10178078B1 patent drawing
  • US10178078B1 patent drawing
  • US10178078B1 patent drawing

AI summary

A secure and transparent digital credential sharing arrangement which utilizes one or more cryptographic levels of indirection to obfuscate a sharing entity's credentials from those entities authorized to share the credentials. A security policy table is provided which allows the sharing entity to selectively authorize or revoke digital credential sharing among a plurality of entities. Various embodiments of the invention provide for secure storage and retrieval of digital credentials from security tokens such as smart cards. The secure sharing arrangement may be implemented in hierarchical or non-hierarchical embodiments as desired.