Digital Identity Key Management for Multi-Mode Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The management of digital currency keys and smart product keys is cumbersome due to their complexity and length, leading to security risks and user inconvenience, as users often forget or confuse multiple keys, and there is a lack of effective solutions to simplify and secure this process.

Innovation Solution

A key management method and apparatus that generates authentication encryption keys based on identity authentication modes, encrypts character decryption keys, and manages these keys through a digital identity system, allowing for secure and convenient access and use of target keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users directly manage digital currency keys and smart product keys, then security can be maintained through proper key protection, but key management becomes cumbersome and complex due to the large number of digits and irregularity of keys

Engineering Contradiction:
Improvekey securityVSAvoidkey management convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary system that includes a key management service and a key chain. The key management service generates encryption keys and manages them on behalf of users, while the key chain stores encrypted versions of these keys. This intermediary structure allows users to access their digital assets without directly handling complex cryptographic keys, thus maintaining security while improving ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The key management system enables self-service through automated key generation, encryption, and management processes. The key management service automatically generates encryption keys when users create accounts or add assets, and the system automatically encrypts and stores these keys in the key chain. Users can recover their keys through biometric authentication or other self-service mechanisms without requiring manual key management, thus improving convenience while maintaining security.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If multiple identity authentication modes are supported for digital identity, then adaptability and versatility improve, but device complexity increases due to the need to manage multiple authentication methods

Engineering Contradiction:
Improveauthentication mode flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal key management system that can handle multiple types of identity authentication modes through a single interface. The key management service is designed to work with various authentication methods (biometric, password, hardware token, etc.) without requiring separate management systems for each type. This multi-functional approach allows the system to support diverse authentication modes while maintaining relatively simple device architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12567963B2Key management method and apparatus
Publication Date: 2026.03.03 BEIJING SURSEN NETWORK TECH
  • US12567963B2 patent drawing
  • US12567963B2 patent drawing
  • US12567963B2 patent drawing

AI summary

Disclosed are a key management method and a key management apparatus, where the key management method includes: acquiring authorization of a user through a first identity authentication mode to generate a first authentication encryption key, where the first identity authentication mode is used for logging into a digital identity; and encrypting at least one character decryption key by using the first authentication encryption key to obtain at least one initially encrypted character decryption key corresponding to the first identity authentication mode, where the at least one character decryption key is in a one-to-one correspondence with at least one character of the digital identity and used to decrypt at least one encrypted target key to obtain at least one target key. In the technical solutions of the present application, an identity authentication mode can be associated with a target key, facilitating a management and use process of the target key.