Remote Credential Exchange for Locked Service Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Providing secure authentication credentials between wireless stations in a WLAN remains a challenge, particularly when user interfaces are malfunctioning or inoperable, and biometric enrollment processes are cumbersome and time-consuming.
Innovation Solution
A method for remote authentication credential exchange is implemented, allowing devices to register in a secure device ecosystem, authenticate with a multi-device ID, and request and receive missing credentials from trusted devices using encrypted messages, including biometric or password information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric enrollment processes are used for authentication, then security is improved, but setup time and complexity increase
Solution Approach 1:
The system performs biometric enrollment and credential provisioning in advance on a first device before the user needs access on a second device. The enrolled biometric data and authentication credentials are securely stored on the first device, enabling rapid authentication on the second device without requiring the user to go through the enrollment process again.
Solution Approach 2:
The system introduces a credential transfer mechanism that acts as an intermediary between the first device (where biometric data is enrolled) and the second device (where authentication is needed). This intermediary process securely transmits and provisions credentials, eliminating the need for direct biometric enrollment on the second device and reducing setup time while maintaining security.
2Reliability
If manual credential entry is required for authentication, then security is maintained, but ease of operation deteriorates when user interfaces are malfunctioning
Solution Approach 1:
The system enables the device to authenticate itself using pre-provisioned credentials and enrolled biometric data without requiring manual user input. The authentication process is automated, with the device independently providing credentials to the authentication service, which is particularly valuable when the user interface is malfunctioning and cannot accept manual input.
Solution Approach 2:
The system uses an intermediary credential transfer mechanism that provisions authentication credentials to the device in advance. This intermediary process eliminates the need for real-time manual credential entry by the user, allowing the device to authenticate automatically even when the user interface is non-functional, while still maintaining security through the use of securely provisioned credentials.
3Reliability
If secure credential transmission is implemented, then security is improved, but device complexity increases
Solution Approach 1:
The system combines multiple security functions into integrated modules: biometric enrollment, credential generation, secure storage, and authentication are merged into cohesive service modules on the devices. This integration reduces the overall system complexity by eliminating the need for separate, standalone components for each security function, while maintaining robust security through the coordinated operation of these merged functions.
Solution Approach 2:
The system introduces a credential transfer service as an intermediary that handles the complex tasks of secure credential generation, encryption, and transmission between devices. This intermediary abstracts the complexity of secure credential management from the individual devices, allowing them to participate in secure authentication without implementing complex security protocols themselves, thus reducing device complexity while maintaining security.
Data Source
AI summary
This disclosure provides methods, components, devices, and systems for providing remote authentication information exchange for a system service in a secure device ecosystem. Some aspects more specifically relate to exchanging credential information between two devices in the secure device ecosystem, including manually entered passwords and stored credentials such as stored biometric credentials. Remote credential information exchanged between the two devices is provided to a system service on one of the devices by updating missing credential information using the remote credential information.


