Passkey Management With Automatic Device Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for managing and sharing authentication credentials, such as passkeys and passwords, are cumbersome and inefficient, consuming user time and device energy, particularly in battery-operated devices, and are difficult to manage in communal settings.

Innovation Solution

Electronic devices are equipped with methods and interfaces that allow for faster and more efficient management and sharing of authentication information, including passkeys and passwords, by utilizing private keys established on different systems and reducing redundant user inputs, while providing improved visual feedback and additional control options.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If existing methods for managing and sharing authentication credentials are used, then security requirements are met, but user time consumption and device energy consumption increase

Engineering Contradiction:
Improveauthentication credential management efficiencyVSAvoiduser time consumption
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically detecting when a user switches between devices and proactively preparing the authentication credential transfer. The patent implements this through automatic device detection and credential offering mechanisms that eliminate the need for users to manually initiate the sharing process, thereby reducing time consumption while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by allowing authentication credentials to be automatically managed and transferred without requiring manual user intervention. The patent describes mechanisms where the system automatically detects device switches, presents credential options, and completes the transfer process based on user preferences set in advance, freeing users from time-consuming manual management tasks

Inventive Principle:
Principle #25Self-service

2Productivity

If existing methods for managing and sharing authentication credentials are used, then security requirements are met, but device energy consumption increases

Engineering Contradiction:
Improveauthentication credential management efficiencyVSAvoiddevice energy consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The system implements periodic action by only activating credential detection and transfer mechanisms when specific conditions are met, such as when a device switch is detected. Rather than continuously monitoring or preparing credentials, the system triggers these energy-intensive operations only when necessary, thereby reducing overall energy consumption while maintaining productivity

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system reduces energy consumption through self-service mechanisms that automatically manage credential transfers without requiring continuous user interaction. Once user preferences are configured, the system autonomously handles detection, presentation, and transfer of credentials, eliminating the need for users to repeatedly engage with energy-consuming interfaces

Inventive Principle:
Principle #25Self-service

3Reliability

If complex user interfaces with multiple key presses are used, then authentication security is maintained, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoiduser interface simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies dynamics by adapting the user interface complexity based on the operational context. When a device switch is detected, the system dynamically presents credential sharing options and guides the user through the process. When no switch is detected, the complex interface elements remain hidden, providing a simple view that does not require multiple key presses, thus maintaining both security and ease of operation

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system introduces an intermediary mechanism that mediates between security requirements and user simplicity. The patent describes a system that acts as an intermediary by automatically detecting device switches and presenting credential options, thereby shielding users from complex security procedures while maintaining authentication security through controlled, guided interactions

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If manual authentication credential input is required, then security control is maintained, but cognitive burden on users increases

Engineering Contradiction:
Improveauthentication controlVSAvoidcognitive burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system reduces cognitive burden through self-service mechanisms that automatically manage authentication credentials. The patent describes how the system automatically detects device switches, retrieves appropriate credentials, and presents them for confirmation, eliminating the need for users to manually recall or input complex authentication information while maintaining security control through user confirmation requirements

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12425394B2Passkey management and sharing
Publication Date: 2025.09.23 APPLE INC
  • US12425394B2 patent drawing
  • US12425394B2 patent drawing
  • US12425394B2 patent drawing

AI summary

The present disclosure generally relates to techniques for managing and sharing authentication information (e.g., passkeys, verification codes, and/or passwords) using electronic devices. A first computing system being associated with a first user account of a first user receives, via one or more input devices, one or more inputs that corresponds to a request to access a remote service that requires authentication, and in response to receiving the one or more inputs that correspond to the request to access the remote service, provides authentication information to the remote service that is based on a private key that is accessible to the first computing system, where the authentication information does not include the private key, the private key was established by a second computer system that is different from the first computer system, and the second computer system is also associated with the first user account.