Hardware Cryptographic Processor for Secure Multi-Device Credential Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity management systems are insecure, particularly when devices are lost or stolen, as they rely on simple passwords or PINs, leading to compromised user identities and access across multiple accounts, with current solutions providing only temporary or inefficient patches.

Innovation Solution

A blockchain-based secure credential and token management system that uses a hardware-based cryptographic processor to create a public-private key pair, restricts attestation tokens to specific devices, and allows delegation of revocation and takeover permissions on a blockchain, enabling secure identity management across multiple devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a simple password or PIN is used to authenticate the user, then the ease of operation is improved, but the reliability is worsened

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity of identity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical/password-based authentication system with a cryptographic system using public-private key pairs. The hardware-based cryptographic processor generates and manages these keys, eliminating the need for users to remember complex passwords while providing stronger security through cryptographic proofs of identity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a blockchain-based intermediary system that mediates authentication between users and service providers. The blockchain stores and verifies credential attestations, acting as a trusted intermediary that eliminates the need for direct password transmission while maintaining ease of use through simplified authentication flows.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the same password is used across multiple sites, then the ease of operation is improved, but the reliability is worsened

Engineering Contradiction:
Improveconvenience of password managementVSAvoidsecurity against compromise
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication credentials into device-specific key pairs stored in hardware security modules. Each device has its own cryptographic identity, eliminating the need to reuse passwords across devices. The blockchain further segments credential verification by storing attestations that are specific to each user-device combination.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables secure copying of credentials across devices through cryptographic delegation. Instead of reusing passwords, users can delegate authentication permissions to multiple devices through blockchain-verified credential transfers, where each device receives a unique cryptographic representation of the user's identity.

Inventive Principle:
Principle #26Copying

3Reliability

If a hardware-based cryptographic processor is used to create credentials, then the reliability is improved, but the device complexity is worsened

Engineering Contradiction:
Improvesecurity of credentialsVSAvoidcomplexity of cryptographic processor
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hardware-based cryptographic processor operates autonomously to generate, store, and manage cryptographic keys without requiring user intervention for complex operations. The processor self-manages the sensitive cryptographic materials, providing security while keeping the user interface simple. The blockchain network also provides self-service by automatically verifying credentials without requiring complex validation logic in each device.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10735197B2Blockchain-based secure credential and token management across multiple devices
Publication Date: 2020.08.04 WORKDAY INC
  • US10735197B2 patent drawing
  • US10735197B2 patent drawing
  • US10735197B2 patent drawing

AI summary

An embodiment herein provides a processor implemented method for blockchain-based secure credential and token management for open identity management that enables a first device to provision at least one additional device to present tokens issued to the first device, that includes i) creating, using a hardware-based cryptographic processor on a first device associated with an end user, a first set of credentials; ii) obtaining and caching at least one attestation token from one or attestation issuing parties, the at least one attestation token is restricted by default to be unusable from any device other than the first device; (iii) providing the at least one attestation token to at least one relying party that is interested in receiving attestations about the end user; and iv) signing a trust record on the blockchain using the first device associated with the end user.