Trusted Mobile Device Credential Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in managing and securely accessing multiple passwords and authentication credentials for various web-based and network-based services, leading to a cumbersome user experience due to the need to remember and carry multiple authentication information.

Innovation Solution

A mobile communications device is used to store and manage security credentials, with a processor, memory, and communication interface to receive requests from client computers, determine responses based on user preferences, and transmit these responses securely, thereby simplifying and securing the authentication process across multiple service applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users manage and store multiple security credentials locally on different devices, then authentication access is improved, but device complexity and user burden increase

Engineering Contradiction:
Improveauthentication accessVSAvoiduser burden
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent consolidates multiple security credentials from various service applications into a single centralized storage location on one mobile device. This merging approach allows users to access multiple services through a single device, eliminating the need to carry and manage multiple separate key fobs or credential storage locations, thereby reducing user burden while maintaining authentication access.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The mobile device is designed to serve multiple functions by storing and managing credentials for diverse service applications (corporate VPN, banking, shopping, entertainment) within a single unified system. This multi-functionality allows one device to replace multiple specialized authentication devices, improving ease of operation without increasing overall complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If users carry multiple key fobs for different services, then service access is improved, but portability and convenience deteriorate

Engineering Contradiction:
Improveservice accessVSAvoidportability
Core Design Contradiction:
Adaptability or versatilityVSWeight of moving object

Solution Approach 1:

The patent combines multiple physical key fobs into a single mobile device that stores credentials for various services. This consolidation maintains the ability to access different services (corporate VPN, banking, shopping sites) while eliminating the need to physically carry multiple separate key fobs, thereby improving portability and convenience.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If credentials are stored on untrusted client computers, then ease of authentication is improved, but security deteriorates

Engineering Contradiction:
Improveauthentication easeVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a trusted mobile device as an intermediary between the user and untrusted client computers. This intermediary stores and manages security credentials securely on the mobile device, which communicates with service applications through the untrusted client computer. This approach maintains authentication ease while protecting credentials from being exposed to potentially malicious client computers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts and isolates security credentials from the untrusted client computer environment and stores them exclusively on the trusted mobile device. This extraction ensures that credentials remain secure and are not exposed to potential security threats on client computers, while still enabling easy authentication through the mobile device's secure storage.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8532620B2Trusted mobile device based security
Publication Date: 2013.09.10 GOOGLE LLC
  • US8532620B2 patent drawing
  • US8532620B2 patent drawing
  • US8532620B2 patent drawing

AI summary

A method for performing user security operations using a mobile communications device includes, storing at least one security credential for a user in the mobile communications device, receiving a request from a client computer to perform an action requiring the stored at least one security credential, wherein the request includes information regarding a service application for which the action is requested, determining a response to the request based upon at least one user configured personal security preference at the mobile communications device, and transmitting the determined response to the client computer. Corresponding system and computer program products are also described.