Distributed Profile Key Management via PIV-D Derived Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for mobile device authentication and network security face challenges due to the lack of card readers in mobile devices, which limits the use of derived credentials and requires multiple certificates for each profile, leading to central key management vulnerabilities and inefficient network bandwidth usage.

Innovation Solution

Implementing distributed key and profile management that allows device-side key generation and sharing of a single certificate across multiple profiles, using a PIV-D application to generate and manage derived credentials locally on the client device, reducing the need for server-side key management and enhancing network security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple certificates are used for each device profile, then authentication reliability is improved, but device complexity and management overhead increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by enabling a single certificate to serve multiple device profiles and authentication purposes. The derived credential system allows one certificate to be used across different profiles (e.g., Wi-Fi, email, cloud access) instead of requiring separate certificates for each profile, thereby reducing management complexity while maintaining authentication reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If server-side key management is used, then centralized control is improved, but network bandwidth consumption and server computational load increase

Engineering Contradiction:
Improvecentralized controlVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts key generation and management operations from the server and places them on the client device. The PIV-D application generates derived credentials locally using the user's PIV card and PIN, eliminating the need for servers to perform computationally intensive cryptographic operations and reducing network bandwidth consumption for key distribution.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system enables self-service by allowing client devices to autonomously generate and manage their own cryptographic keys and credentials. The PIV-D application on the client device performs key derivation and certificate generation without requiring continuous server intervention, reducing server computational load and network bandwidth consumption while maintaining security.

Inventive Principle:
Principle #25Self-service

3Reliability

If frequent key distribution is performed, then security is improved, but network bandwidth usage and processing time increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by generating and storing derived credentials locally on the client device during initial setup. The PIV-D application creates and caches the necessary cryptographic material beforehand, allowing subsequent authentication operations to proceed without frequent key distribution, thereby reducing processing time while maintaining security through proper credential management.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11443023B2Distributed profile and key management
Publication Date: 2022.09.13 OMNISSA LLC
  • US11443023B2 patent drawing
  • US11443023B2 patent drawing
  • US11443023B2 patent drawing

AI summary

Disclosed are various examples for distributed profile and key management. In one example, a client device can include an agent application and a PIV-D application. The agent application can receive a partially populated device profile generated by a management service to configure a setting on the client device. The PIV-D application can generate a derived credential and provide the derived credential to the agent application. The agent application can modify the partially populated device profile to include the credential to create a fully populated device profile and configure the client device in accordance with the fully populated device profile.