Secondary Device Credential Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in providing strong authentication for network-connected devices to prevent unauthorized access to security-sensitive information.

Innovation Solution

The method involves enhanced authentication techniques that leverage interactions between a primary communication device and other secondary devices, using credential data from secondary devices to generate cryptograms for authorization requests, and comparing recent interactions with historic patterns to assess risk.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used, then device connectivity and ease of operation are maintained, but security and reliability are insufficient against unauthorized access

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces secondary devices as intermediaries in the authentication process. These devices provide credential data that mediates between the primary device and the authorization server, enhancing security without requiring the primary device to directly handle all authentication complexity. The secondary devices act as trusted intermediaries that contribute to the cryptographic verification process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into multiple independent components: primary devices that initiate authentication, secondary devices that provide credential data, and authorization servers that verify cryptograms. This segmentation distributes the authentication burden across multiple devices, improving reliability while maintaining manageable complexity through modular design.

Inventive Principle:
Principle #1Segmentation

2Reliability

If stronger authentication schemes are implemented, then reliability and security are improved, but device complexity and operational difficulty increase

Engineering Contradiction:
Improveauthorization confidenceVSAvoidauthentication process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables secondary devices to automatically provide their credential data to the primary device without requiring manual user configuration or intervention. The devices self-manage their authentication credentials and automatically participate in the cryptographic verification process, maintaining ease of operation while strengthening authentication.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Secondary devices pre-store credential data and cryptographic keys before authentication is needed. This preliminary setup allows the authentication process to proceed smoothly during actual use, as the credential data is already available and prepared for rapid verification by the authorization server.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple devices are involved in authentication, then security is enhanced through secondary device interactions, but system complexity and coordination requirements increase

Engineering Contradiction:
Improveauthentication strengthVSAvoidmulti-device coordination
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs secondary devices with universal functionality to provide credential data across different authentication scenarios. These devices can serve multiple purposes: storing credentials, providing cryptographic verification, and participating in various authentication contexts. This multi-functionality reduces overall system complexity by using a standardized approach across diverse devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4271016B1Enhanced authentication based on secondary device interactions
Publication Date: 2025.02.19 VISA INTERNATIONAL SERVICE ASSOCIATION
  • EP4271016B1 patent drawingFigure 1
  • EP4271016B1 patent drawingFigure 2
  • EP4271016B1 patent drawingFigure 3

AI summary

Enhanced authentication techniques may include receiving device data of a secondary device by a primary device, transmitting a provision request to an authorization server to request account credentials associated with an account, receiving a provision response from the authorization server comprising encrypted account credentials comprised of a first part and a second part and a shared key associated with the primary device, storing by the primary device the shared key and the first part of the encrypted account credentials, and transmitting the second part of the encrypted account credentials of the secondary device for storage.