Terminal-Based Application Secret Reset Using Secure Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for resetting application secrets, such as passwords, are inadequate due to ease of use and security concerns, particularly with solutions like email addresses and recovery keys.

Innovation Solution

A method for resetting application secrets using a reset element stored in the terminal's secure environment, requiring user authentication and employing cryptographic processing with encryption keys, either symmetric or asymmetric, and optionally external authentication factors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If external proof factors (email, phone, recovery key) are used for secret reset, then the secret can be reset, but security is compromised or usability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The invention extracts the reset functionality from external systems (email servers, phone networks) and brings it into the terminal's secure environment. The reset element is stored locally in a secure element or trusted execution environment, eliminating dependency on external proof factors and their associated security risks while maintaining ease of use through local authentication.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The secure environment acts as an intermediary between the user and the application secret reset process. Instead of directly using external factors like email or phone, the user authenticates through the secure environment which then mediates the reset operation, providing both security and usability benefits.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If complex recovery keys are stored for secret reset, then security is improved, but ease of use deteriorates due to storage and availability requirements

Engineering Contradiction:
ImprovesecurityVSAvoidease of use
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The secure environment provides self-service authentication capabilities using biometric data or device-locked credentials that are already stored in the terminal. Users authenticate themselves through the secure environment without needing to manually store or retrieve complex recovery keys, as the system automatically manages the authentication process using pre-stored biometric templates or device credentials.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If email address is used as proof factor, then secret reset is enabled, but security deteriorates due to synchronization on terminal

Engineering Contradiction:
Improveease of useVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The invention removes the email address dependency from the reset process entirely. Instead of using email as a proof factor, the reset element is extracted and stored in the terminal's secure environment, eliminating the security vulnerability of email synchronization while maintaining ease of use through local authentication mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12542657B2Reinitialization of an application secret by way of the terminal
Publication Date: 2026.02.03 SHELL OIL CO
  • US12542657B2 patent drawing
  • US12542657B2 patent drawing
  • US12542657B2 patent drawing

AI summary

A method for reinitializing an application secret of an application executed by a terminal, the terminal including a security infrastructure to securely manage data for authenticating a user by the terminal. The application is connected to an application server. The method includes, after the user requests reinitialization of the application secret from the application, the security infrastructure receiving a request to cryptographically process a verification element by using an element for reinitializing the application secret stored beforehand in the security infrastructure; authenticating the user based on data entered by the user and authentication data stored in the security infrastructure; and if the user is authenticated; cryptographically processing the element for verifying the application secret to obtain an element for validating the reinitialization, which is sent to the application so that the application server validates the element and, if applicable, executes a process of reinitializing the application secret.