Stylus Digital Certificate Authentication for Touch Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional user authentication in tablets involves a multi-step, multi-device process, which can be cumbersome and interruptive, especially for users who primarily engage in digital ink activities, as they need to switch between devices for login and may require typing codes or using fingerprint recognition.

Innovation Solution

A stylus device equipped with a digital certificate module that wirelessly transmits the certificate and digital ink data to a touch device for seamless user authentication, eliminating the need for manual code entry and providing an additional secure authentication factor through digital ink inputs like signatures or drawings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional multi-step authentication processes are used, then security is maintained, but user convenience and operational efficiency deteriorate

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines multiple authentication factors (biometric data, digital certificate, device identifiers) into a single integrated authentication process. The stylus device merges storage of cryptographic credentials with the authentication interface, eliminating the need for separate authentication devices or manual code entry, thus maintaining security while improving user convenience.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The stylus device is designed to perform multiple functions: it serves as both a digital ink input tool and an authentication credential storage device. The same device users interact with for drawing and note-taking also securely stores and transmits authentication credentials, eliminating the need for separate authentication hardware and simplifying the user experience.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multi-device authentication processes are used, then security is improved, but process complexity and time consumption increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into distinct functional modules: biometric sensing module, cryptographic credential storage module, wireless communication module, and authentication protocol module. This segmentation allows each component to be optimized independently and facilitates secure modular authentication across multiple devices without requiring complex integrated systems.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The stylus device acts as an intermediary between the user's biometric data and the authentication system. It securely stores digital certificates and cryptographic keys, then mediates the authentication process by transmitting these credentials to the target device, simplifying the overall authentication architecture while maintaining multi-device security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If manual code entry or fingerprint recognition is required, then authentication security is maintained, but operational efficiency and user experience deteriorate

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by pre-enrolling biometric data and pre-generating digital certificates during device setup. These authentication credentials are stored in advance in the stylus device, enabling rapid authentication without requiring real-time manual code entry or repeated fingerprint scanning, thus improving authentication speed while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system enables self-service by automatically capturing biometric data and generating authentication credentials without requiring manual intervention. The stylus device autonomously manages cryptographic keys and certificates, performing self-updates and self-authentication operations, which eliminates manual code entry and accelerates the authentication process.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3411822B1Authenticating users via data stored on stylus devices
Publication Date: 2020.12.09 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3411822B1 patent drawingFigure 1
  • EP3411822B1 patent drawingFigure 2
  • EP3411822B1 patent drawingFigure 3

AI summary

An example method includes receiving a digital certificate corresponding to a user at a stylus device. The method includes transmitting the digital certificate and associated digital ink data to a touch device to authenticate the user based at least on the digital certificate and the associated digital ink data in response to detecting that the stylus device is within a threshold range of the touch device.