Persona Device Certificate Management System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies lack an effective method for extending trust between computing devices based on user personas and device identities, which is essential for secure interactions and authorization across various devices and systems.

Innovation Solution

A persona-device certificate management system that utilizes hardware-based root of trust features to generate and manage digital certificates by combining user persona information with device keys, enabling secure authentication and authorization across devices and systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-based root of trust features are used to secure authentication, then security reliability is improved, but device complexity increases due to dedicated hardware modules

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines user persona information with device identity information to create a unified certificate that integrates both authentication factors. This merging approach allows the system to leverage hardware-based root of trust features for security while avoiding the need for separate hardware modules for each authentication factor, thus improving security reliability without proportionally increasing device complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The generated certificate serves multiple functions: it authenticates the device identity, verifies user persona information, and enables secure interactions across different systems. This multi-functionality reduces the need for separate authentication mechanisms, thereby maintaining high security reliability without requiring additional dedicated hardware modules for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If digital certificates are generated combining user persona and device identity, then trust extension capability is improved, but system complexity increases

Engineering Contradiction:
Improvetrust extension capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a certificate management system that acts as an intermediary between the device, user persona information, and target systems. This intermediary handles the complex tasks of certificate generation, validation, and management, thereby enabling robust trust extension capability while shielding the end systems from the underlying complexity of certificate operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transforms multiple authentication parameters (device identity, user persona information, biometric data) into a single standardized certificate format. This parameter transformation simplifies the trust extension process by converting complex multi-factor authentication data into a universally acceptable certificate structure that can be easily validated across different systems.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If biometric data is captured and processed for persona verification, then authentication security is improved, but processing time increases

Engineering Contradiction:
Improveauthentication securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary processing of biometric data during the certificate generation phase, extracting and encoding essential persona verification features in advance. This preliminary action prepares the biometric information for rapid comparison during subsequent authentication operations, thereby maintaining high authentication security while significantly reducing the time required for actual verification processes.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11683181B2Persona and device based certificate management
Publication Date: 2023.06.20 T MOBILE US INC
  • US11683181B2 patent drawing
  • US11683181B2 patent drawing
  • US11683181B2 patent drawing

AI summary

A user device implements a certificate authority for issuing digital certificates that extend to other computing devices a level of trust to a particular user paired with the user device. The user device may obtain user persona information, generate a user key, and combine the user key with a device key for the generation of a digital certificate. The computing device may further transmit the digital certificate to a certificate management system, which manages interactions between other computing devices and the user device or authorizes operation of other computing devices by the particular user based on the digital certificate.