Multi-User Credential Management with Anonymous Suspension Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face inefficiencies in managing multiple user credentials on a single electronic device, particularly in securing and suspending transactions when the device is lost or stolen, while maintaining user privacy and security.

Innovation Solution

Implementing a system with user-anonymous suspension tokens that associate credentials with a particular user at the credential protection subsystem but not at the device protection subsystem, preventing the linking of users to a specific device, and using a device protection server to manage credential suspension.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple user credentials are stored on a single electronic device, then credential management efficiency improves, but security and privacy protection deteriorates

Engineering Contradiction:
Improvecredential management efficiencyVSAvoidsecurity and privacy protection
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments credential management into two independent subsystems: a credential protection subsystem that stores and manages credentials locally on the device, and a device protection subsystem that handles device-level security operations. This segmentation allows efficient local credential access while maintaining centralized security control, resolving the contradiction between management efficiency and security protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism using anonymous suspension tokens that mediate between the credential protection subsystem and device protection subsystem. These tokens enable the device protection subsystem to suspend credentials without knowing which specific users or credentials are affected, thus maintaining security while enabling effective credential management across multiple users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If device protection service suspends all credentials when device is lost, then security protection improves, but user privacy deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts the linking information between users and suspension tokens from the device protection subsystem. The anonymous suspension tokens are stored in the credential protection subsystem where they maintain associations with specific users and credentials, while the device protection subsystem only holds the tokens without knowing their associations. This extraction prevents privacy loss while maintaining security suspension capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The anonymous suspension token acts as an intermediary that decouples the device protection subsystem from user identity information. The token enables credential suspension without revealing which user's credentials are being suspended, thus protecting user privacy while maintaining effective security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If user-specific credential suspension is implemented, then privacy protection improves, but device complexity increases

Engineering Contradiction:
Improveprivacy protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses anonymous suspension tokens as simplified copies or representations of user-credential associations. Instead of storing complex user identity data in the device protection subsystem, the system uses anonymous tokens that replicate the necessary suspension functionality without the complexity of user identification, thus maintaining privacy while reducing system complexity.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12388805B2Managing credentials of multiple users on an electronic device
Publication Date: 2025.08.12 APPLE INC
  • US12388805B2 patent drawing
  • US12388805B2 patent drawing
  • US12388805B2 patent drawing

AI summary

Systems, methods, and computer-readable media for managing credentials of multiple users on an electronic device are provided.