Encrypted Credential Sharing Across Mobile Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges in securely and reliably sharing credentials across multiple mobile communication devices in wireless communication networks, as existing solutions often require storing credentials in unencrypted form or lack efficient methods for secure transfer between devices.
Innovation Solution
A network infrastructure stores encrypted credential objects and forms of credential keys, with each device key stored on individual mobile devices, allowing devices to decrypt and share credentials securely through a key exchange process, ensuring that credentials are kept encrypted and only accessible via authorized devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If credentials are stored in unencrypted form for easy access, then ease of operation is improved, but security is worsened
Solution Approach 1:
The credential system is segmented into multiple components: credential objects, credential keys, and device keys. Each component serves a specific function and is stored separately. The credential objects are encrypted with credential keys, which are in turn encrypted with device-specific keys. This segmentation allows secure storage while maintaining operational efficiency through structured access procedures.
Solution Approach 2:
The patent introduces encrypted credential keys as an intermediary layer between the credential objects and the devices. Instead of directly storing credentials in plaintext or using a single master key, the system uses multiple encrypted forms of credential keys that act as mediators. Each device has its own encrypted credential key that it can decrypt to access the credential objects, providing both security and ease of access.
2Reliability
If credentials are encrypted for security, then security is improved, but ease of operation is worsened
Solution Approach 1:
The system performs preliminary encryption actions by pre-generating multiple encrypted forms of credential keys for different devices before actual credential access is needed. When a device needs to access credentials, it already has its specific encrypted credential key ready, eliminating the need for real-time encryption/decryption operations and maintaining ease of operation while ensuring security.
Solution Approach 2:
The patent changes the parameter of encryption from a single static state to multiple dynamic states. Instead of using one encryption method or key, the system employs multiple encrypted forms of credential keys, each tailored to specific devices. This parameter change allows the system to maintain strong encryption while adapting to different device contexts, thereby preserving ease of operation.
3Adaptability or versatility
If multiple devices share credentials, then adaptability is improved, but security is worsened due to increased access points
Solution Approach 1:
The patent applies local quality by providing each device with its own device-specific encrypted credential key. Instead of using a uniform access method for all devices, the system tailors the encryption to each device's specific context and security requirements. This localized approach allows multiple devices to access credentials securely while maintaining individual device autonomy and reducing the security risks associated with centralized credential management.
Solution Approach 2:
The credential access system is segmented into device-specific components. Each device has its own encrypted credential key that is uniquely tied to that device's identity and security context. This segmentation ensures that even if one device is compromised, the security of other devices remains intact, as each device's access credentials are independent and cannot be easily transferred or replicated.
Data Source
AI summary
Techniques for use in sharing a plurality of credential objects of a user account amongst a plurality of mobile devices operative in a wireless network are described. In one illustrative example, a network infrastructure (e.g. a cloud) stores a plurality of encrypted credential objects in association with the user account. Each encrypted credential object is encrypted with a credential key. The network infrastructure also stores a plurality of encrypted forms of the credential key in association with the user account. Each encrypted form of the credential key is encrypted with a respective one of a plurality of device keys. Each device key is stored at respective one of the mobile devices. The network infrastructure provides, to the mobile devices, access to the encrypted credential key and the encrypted credential objects.


