Multi-User Credential Management with Anonymous Suspension Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face inefficiencies in managing multiple user credentials on a single electronic device, particularly in securing and suspending transactions when the device is lost or stolen, while maintaining user privacy and security.
Innovation Solution
Implementing a system with user-anonymous suspension tokens that associate credentials with a particular user at the credential protection subsystem but not at the device protection subsystem, preventing the linking of users to a specific device, and using a device protection server to manage credential suspension.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multiple user credentials are stored on a single electronic device, then credential management efficiency improves, but security and privacy protection deteriorates
Solution Approach 1:
The patent segments credential management into two independent subsystems: a credential protection subsystem that stores and manages credentials locally on the device, and a device protection subsystem that handles device-level security operations. This segmentation allows efficient local credential access while maintaining centralized security control, resolving the contradiction between management efficiency and security protection.
Solution Approach 2:
The patent introduces an intermediary mechanism using anonymous suspension tokens that mediate between the credential protection subsystem and device protection subsystem. These tokens enable the device protection subsystem to suspend credentials without knowing which specific users or credentials are affected, thus maintaining security while enabling effective credential management across multiple users.
2Reliability
If device protection service suspends all credentials when device is lost, then security protection improves, but user privacy deteriorates
Solution Approach 1:
The patent extracts the linking information between users and suspension tokens from the device protection subsystem. The anonymous suspension tokens are stored in the credential protection subsystem where they maintain associations with specific users and credentials, while the device protection subsystem only holds the tokens without knowing their associations. This extraction prevents privacy loss while maintaining security suspension capability.
Solution Approach 2:
The anonymous suspension token acts as an intermediary that decouples the device protection subsystem from user identity information. The token enables credential suspension without revealing which user's credentials are being suspended, thus protecting user privacy while maintaining effective security control.
3Reliability
If user-specific credential suspension is implemented, then privacy protection improves, but device complexity increases
Solution Approach 1:
The patent uses anonymous suspension tokens as simplified copies or representations of user-credential associations. Instead of storing complex user identity data in the device protection subsystem, the system uses anonymous tokens that replicate the necessary suspension functionality without the complexity of user identification, thus maintaining privacy while reducing system complexity.
Data Source
AI summary
Systems, methods, and computer-readable media for managing credentials of multiple users on an electronic device are provided.


