Passkey Sharing Across Devices With Pre-Established Private Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for managing and sharing authentication credentials, such as passkeys and passwords, are cumbersome and inefficient, consuming user time and device energy, particularly in battery-operated devices, and are difficult to manage in communal settings.

Innovation Solution

Electronic devices are equipped with faster and more efficient methods and interfaces for managing and sharing authentication information, including methods that reduce redundant user inputs and conserve power by using private keys established by other systems, and interfaces that provide visual feedback and additional control options without cluttering the user interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If existing methods for managing and sharing authentication credentials are used, then authentication security is maintained, but user time consumption and device energy consumption increase significantly

Engineering Contradiction:
Improveuser time consumptionVSAvoidauthentication security
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system performs preliminary actions by establishing authentication credentials in advance through a setup process where a first device generates credentials and a second device receives and stores them. This preliminary credential establishment eliminates the need for time-consuming manual entry during actual authentication, reducing user time consumption while maintaining security through pre-configured cryptographic pairs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements copying by generating cryptographic credential pairs where a public key is created from a private key. The public key is copied and transmitted to the second device, while the private key remains securely stored in the first device. This copying mechanism enables efficient authentication without requiring users to manually handle or enter complex credentials, significantly reducing time consumption while preserving security through asymmetric cryptography.

Inventive Principle:
Principle #26Copying

2Ease of operation

If complex user interfaces with multiple key presses are used for credential management, then authentication control is enhanced, but ease of operation deteriorates

Engineering Contradiction:
Improveease of credential managementVSAvoidinterface complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system implements self-service by enabling automatic authentication through pre-configured credentials. During setup, the first device automatically generates credential pairs and the second device automatically receives and stores them. During authentication, the system automatically uses the stored credentials without requiring users to manually enter complex information or navigate through multiple interface steps, greatly enhancing ease of operation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary mechanism through the use of cryptographic credential pairs that mediate between users and the authentication system. Instead of users directly interacting with complex authentication protocols, the pre-established credential pairs serve as intermediaries that automatically handle the authentication process, simplifying user interaction while maintaining security controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If manual authentication credential entry is required, then authentication accuracy is improved, but productivity deteriorates

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidauthentication accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system performs preliminary credential configuration during a setup phase, where authentication credentials are generated, transmitted, and stored in advance. This preliminary action eliminates the need for manual entry during actual authentication operations, significantly improving productivity. The pre-configured credentials ensure accuracy by using cryptographically generated values rather than user-typed input, which is prone to errors.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the mechanical system of manual keyboard entry with an automated electronic credential retrieval and submission process. Instead of users physically typing authentication information, the system electronically retrieves pre-stored credentials and submits them automatically. This substitution dramatically improves productivity by eliminating repetitive manual typing while maintaining high accuracy through the use of cryptographically secure pre-generated credentials.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250358279A1Passkey management and sharing
Publication Date: 2025.11.20 APPLE INC
  • US20250358279A1 patent drawing
  • US20250358279A1 patent drawing
  • US20250358279A1 patent drawing

AI summary

The present disclosure generally relates to techniques for managing and sharing authentication information (e.g., passkeys, verification codes, and/or passwords) using electronic devices. A first computing system being associated with a first user account of a first user receives, via one or more input devices, one or more inputs that corresponds to a request to access a remote service that requires authentication, and in response to receiving the one or more inputs that correspond to the request to access the remote service, provides authentication information to the remote service that is based on a private key that is accessible to the first computing system, where the authentication information does not include the private key, the private key was established by a second computer system that is different from the first computer system, and the second computer system is also associated with the first user account.