IoT Password Manager Secure Credential Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IoT systems face challenges in securely providing passwords and managing secure communication channels, particularly in scenarios where multiple devices and online services require user authentication, leading to complexity and insecurity in password management.

Innovation Solution

An IoT system that utilizes a secure communication protocol, including public key infrastructure and symmetric key exchange, to establish encrypted channels between IoT devices, hubs, and services, allowing for secure password storage and transmission, and enables secure pairing and encryption without traditional pairing methods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional pairing methods are used for device authentication, then device compatibility is maintained, but security is compromised and password management becomes complex

Engineering Contradiction:
ImprovesecurityVSAvoidpassword management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a password manager as an intermediary component that securely stores and manages passwords for multiple online services. This mediator handles authentication credentials, allowing devices to authenticate without users manually managing complex password schemes, thus improving security while reducing management complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical pairing methods (manual password entry, device-to-device pairing) with cryptographic key exchange mechanisms and automated authentication protocols. This substitution eliminates the need for users to manually handle passwords, enhancing security through cryptographic methods while simplifying the user experience

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If multiple authentication methods are implemented across devices, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service authentication where the password manager automatically retrieves and inputs credentials without user intervention. The system autonomously manages authentication across multiple devices and services, maintaining high security through cryptographic methods while providing seamless user experience as if no authentication were needed

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal authentication system that works across multiple devices, platforms, and online services through standardized cryptographic protocols. The password manager serves multiple functions including credential storage, key exchange, and automated authentication, eliminating the need for separate authentication mechanisms for each service while maintaining security

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If secure encryption protocols are used for communication, then data security is improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidcommunication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the encryption system into modular components: a password manager module for credential management, a cryptographic module for key exchange and encryption, and integration layers for different devices. This segmentation allows complex security protocols to be implemented as manageable, reusable modules, maintaining high security while reducing overall system complexity through modular architecture

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10841759B2Securely providing a password using an internet of things (IoT) system
Publication Date: 2020.11.17 AFERO INC
  • US10841759B2 patent drawing
  • US10841759B2 patent drawing
  • US10841759B2 patent drawing

AI summary

An apparatus and method are described for securely providing a User ID and/or password to an IoT device. For example, one embodiment of a method comprises: receiving at an Internet of Things (IoT) service a request from a mobile device over a first communication channel to transmit credentials for a particular online service to an IoT device, responsively encrypting the credentials to generate encrypted credentials and transmitting the encrypted credentials to the IoT device over a second communication channel, decrypting the encrypted credentials at the IoT device, and providing the credentials by the IoT device to a computer over a third communication channel, the computer causing the credentials to be provided to the online service to authenticate the user.