Mobile Device Credential Management via Short-Range Network
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing credential management systems are inadequate as they either compromise security when using shared credentials, lack convenience with written records, require frequent master password entry, or rely on third-party cloud security and internet access.
Innovation Solution
A method involving a mobile device that stores encrypted authentication data and encryption keys, allowing secure and convenient authentication across devices via a short-distance network, using an authentication service to decrypt and transmit credentials to connected devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If cloud-based credential management service is used, then data accessibility from multiple devices is improved, but security and reliability depend on third-party cloud and require internet access
Solution Approach 1:
The patent introduces a local credential management system that acts as an intermediary between the user's devices and external services. Instead of relying directly on cloud-based services, the system stores encrypted credentials locally on each device and manages authentication independently, thereby maintaining security without requiring internet access while still enabling cross-device accessibility.
2Ease of operation
If local computer credential management software is used, then convenience is improved with automatic credential input, but users must enter master password frequently or cache in memory
Solution Approach 1:
The system implements self-service authentication by automatically managing credential retrieval and injection without requiring user intervention. The local credential manager autonomously handles authentication processes, retrieving stored credentials and injecting them into applications without prompting users to enter passwords, thereby eliminating time loss associated with frequent password entry.
3Reliability
If written record of credentials is kept, then security and privacy are improved, but convenience deteriorates requiring carrying notebook and manual input
Solution Approach 1:
The patent replaces the mechanical system of physical written records with an electronic credential management system. Instead of manually writing and carrying credentials in a notebook, the system uses encrypted digital storage on devices, automatically retrieving and injecting credentials electronically, thereby maintaining security while dramatically improving convenience by eliminating physical carrying and manual typing.
4Ease of operation
If same credentials are used across multiple systems, then ease of operation is improved with fewer credentials to memorize, but security worsens as one compromise affects all systems
Solution Approach 1:
The system segments credential management by creating unique encrypted credentials for each service or application while maintaining centralized management. Instead of using the same credentials across all systems, the system generates distinct credentials for each target system, all stored and managed locally on the user's devices. This segmentation ensures that if one credential is compromised, only that specific service is affected while others remain secure.
Data Source
AI summary
Methods of short-distance network electronic authentication are described. In one embodiment, a method includes storing encrypted authentication data for a user and a corresponding encryption key on a mobile device; establishing electronic communication between the mobile device and a computer via a short distance network; detecting a request for user-specific authentication data from a third-party application running on the computer; requesting, via an authentication client on the computer, authentication credentials from an authentication service running on the mobile device; accessing, via the authentication service, in response to the requesting step, the encrypted authentication data and encryption key; decrypting the authentication data using the encryption key via the authentication service; transmitting the decrypted authentication data to the authentication client on the client computer; passing the decrypted authentication data from the authentication client to the third-party application; and authenticating the user in the third-party application.


