Authentication Credential Transfer via Proximity Trust Inheritance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for provisioning and managing authentication credentials across multiple devices are costly and require physical presence, especially when transferring trust relationships from one device to another, which is inefficient and logistically cumbersome.

Innovation Solution

Establishing a new trust relationship between an authentication server and a destination authentication device based on an existing trust relationship, using public-private key pairs and proximity verification techniques, allowing the destination device to inherit the trust level of the source device, thereby eliminating the need for physical presence and reducing logistical complexities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional credential provisioning procedures are used for replacement or backup authentication devices, then authentication security is maintained, but operational cost and logistical complexity increase due to requiring physical presence of user and authorized staff

Engineering Contradiction:
Improveoperational efficiencyVSAvoidprovisioning procedure complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by establishing trust relationships in advance between authentication devices. When a device needs replacement or backup, the trust relationship has already been preliminarily established through proximity-based verification, eliminating the need for costly in-person provisioning procedures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements copying by transferring trust relationships from a source authentication device to a destination device. The destination device inherits the trust credentials and identity assurance level of the source device through cryptographic key pair sharing, creating a duplicate trust relationship without requiring re-provisioning.

Inventive Principle:
Principle #26Copying

2Reliability

If in-person provisioning meetings are conducted for each authentication device, then credential security is ensured, but time consumption and operational cost increase

Engineering Contradiction:
Improvecredential securityVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces the mechanical system of in-person meetings with cryptographic mechanisms. Trust relationships are established through digital key pair exchange and proximity verification using electromagnetic signals, substituting physical presence requirements with electronic verification methods that maintain security while reducing time consumption.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system introduces an intermediary approach where the source authentication device acts as a mediator to establish trust with the destination device. Instead of requiring authorized staff to physically provision each device, the source device mediates the trust relationship establishment through automated cryptographic protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple authentication devices are provisioned independently, then each device has secure credentials, but the provisioning process becomes logistically cumbersome and costly

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the provisioning process by allowing multiple authentication devices to share a common trust relationship. Instead of independently provisioning each device, the system combines the provisioning operation into a single process where the source device establishes trust that automatically extends to destination devices through cryptographic inheritance.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements universality by creating a multi-functional trust relationship that serves multiple authentication devices simultaneously. A single trust establishment operation provides security credentials to the source device and can be inherited by multiple destination devices, making the provisioning system versatile and reducing operational complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240430077A1Managing authentication credentials in multiple devices
Publication Date: 2024.12.26 TRUU INC
  • US20240430077A1 patent drawing
  • US20240430077A1 patent drawing
  • US20240430077A1 patent drawing

AI summary

An authentication server receives a request to access an authentication server from a first device. The authentication server receives one or more proximity signals transmitted from the first device and one or more proximity signals transmitted from a second device. The second device has a trust relationship with the authentication server. The authentication server confirms that the first device and the second device are in proximity to each other based on the one or more proximity signals transmitted from the first device and second device. The authentication server verifies the trust relationship with the second device by decrypting a signed message received from the second device after confirmation that the first device and the second device are in proximity to each other. The authentication server updates a trust relationship between the first device and the server based on the verified trust relationship between the second device and the server.