Secondary Device Credential Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in providing strong authentication for network-connected devices to prevent unauthorized access to security-sensitive information.
Innovation Solution
The method involves enhanced authentication techniques that leverage interactions between a primary communication device and other secondary devices, using credential data from secondary devices to generate cryptograms for authorization requests, and comparing recent interactions with historic patterns to assess risk.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used, then device connectivity and ease of operation are maintained, but security and reliability are insufficient against unauthorized access
Solution Approach 1:
The patent introduces secondary devices as intermediaries in the authentication process. These devices provide credential data that mediates between the primary device and the authorization server, enhancing security without requiring the primary device to directly handle all authentication complexity. The secondary devices act as trusted intermediaries that contribute to the cryptographic verification process.
Solution Approach 2:
The authentication system is segmented into multiple independent components: primary devices that initiate authentication, secondary devices that provide credential data, and authorization servers that verify cryptograms. This segmentation distributes the authentication burden across multiple devices, improving reliability while maintaining manageable complexity through modular design.
2Reliability
If stronger authentication schemes are implemented, then reliability and security are improved, but device complexity and operational difficulty increase
Solution Approach 1:
The system enables secondary devices to automatically provide their credential data to the primary device without requiring manual user configuration or intervention. The devices self-manage their authentication credentials and automatically participate in the cryptographic verification process, maintaining ease of operation while strengthening authentication.
Solution Approach 2:
Secondary devices pre-store credential data and cryptographic keys before authentication is needed. This preliminary setup allows the authentication process to proceed smoothly during actual use, as the credential data is already available and prepared for rapid verification by the authorization server.
3Reliability
If multiple devices are involved in authentication, then security is enhanced through secondary device interactions, but system complexity and coordination requirements increase
Solution Approach 1:
The patent designs secondary devices with universal functionality to provide credential data across different authentication scenarios. These devices can serve multiple purposes: storing credentials, providing cryptographic verification, and participating in various authentication contexts. This multi-functionality reduces overall system complexity by using a standardized approach across diverse devices.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Enhanced authentication techniques may include receiving device data of a secondary device by a primary device, transmitting a provision request to an authorization server to request account credentials associated with an account, receiving a provision response from the authorization server comprising encrypted account credentials comprised of a first part and a second part and a shared key associated with the primary device, storing by the primary device the shared key and the first part of the encrypted account credentials, and transmitting the second part of the encrypted account credentials of the secondary device for storage.