Device-User Key Registration for Phishing-Resistant Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems rely solely on device or user certificates for access, which are agnostic to the device/user combination, leaving them vulnerable to fraudulent acts like phishing and man-in-the-middle attacks, and lack secure mechanisms for initial and continued access.

Innovation Solution

A trust anchor for both the device and user, combined with a public/private key pair generated at the device, is used to register a unique device/user identifier at a Resource Management System (RMS), enabling secure initial and continued access to services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device or user certificates are used for access control, then access to services is enabled, but security is compromised due to vulnerability to phishing and man-in-the-middle attacks

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability to phishing and man-in-the-middle attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent merges device certificates and user certificates into a unified device-user certificate pair that is jointly issued by the resource management system. This combination ensures that both device and user must be authenticated together, eliminating the vulnerability where either certificate alone could be exploited in phishing or man-in-the-middle attacks. The combined certificate creates a mutual authentication mechanism that binds the device and user identity together.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The resource management system acts as an intermediary that issues and manages the device-user certificate pairs. This intermediary controls the entire authentication process, validating both device and user credentials before issuing the combined certificate. The intermediary role ensures that only authenticated device-user combinations gain access, preventing direct trust between devices and users that could be exploited by attackers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If device-user combination identification is implemented, then access control precision is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The device-user certificate pair serves multiple functions: it authenticates the device, authenticates the user, establishes the device-user binding, and enables access control. By making the certificate multi-functional, the system achieves precise device-user combination identification without requiring separate authentication mechanisms for each function, thereby reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the authentication parameter from separate device certificate and user certificate to a unified device-user certificate pair. This parameter change consolidates multiple authentication steps into a single operation, improving precision in identifying device-user combinations while simplifying the authentication process and reducing system complexity.

Inventive Principle:
Principle #35Parameter changes

3Stability of the object's composition

If centralized access control is implemented, then IT policy consistency is improved, but management workload increases

Engineering Contradiction:
ImproveIT policy consistencyVSAvoidmanagement time
Core Design Contradiction:
Stability of the object's compositionVSLoss of time

Solution Approach 1:

The resource management system automatically manages device-user certificate pairs without requiring manual intervention for each authentication event. The system self-services by automatically issuing certificates, validating credentials, and controlling access based on predefined policies. This automation maintains IT policy consistency while significantly reducing the manual management workload and time investment.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-establishing device-user certificate pairs and policies before access events occur. Policies are predefined and certificates are issued in advance with embedded access rights. When access events occur, the system simply validates the pre-established certificates against the pre-defined policies, eliminating the need for real-time manual policy application and reducing management time while ensuring consistency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20260058795A1Registering and utilizing a device user key
Publication Date: 2026.02.26 JUMPCLOUD INC
  • US20260058795A1 patent drawing
  • US20260058795A1 patent drawing
  • US20260058795A1 patent drawing

AI summary

Mechanisms for resource management are described. A trust anchor for a device may be obtained. A trust anchor for a user may be obtained. A public key of the device that corresponds to a private key stored in a cryptographic component internal to the device may be generated. The public key of the device may be registered, with a service operated by a resource management system, to a combination of the device and user. Registering the public key of the device may include sending, to the service operated by the resource management system, a registration message that indicates the trust anchor for the device, the trust anchor for the user, and the public key of the device.